Navigation Block with Mega Menu Security & Risk Analysis

wordpress.org/plugins/getwid-megamenu

Build better navigation menus with the WordPress mega menu blocks.

1K active installs v1.0.7 PHP 5.6+ WP 5.7+ Updated Jul 16, 2025
blockmega-menumegamenunavigationwordpress-menu
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 19, 2025
Safety Verdict

Is Navigation Block with Mega Menu Safe to Use in 2026?

Generally Safe

Score 99/100

Navigation Block with Mega Menu has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 19, 2025Updated 8mo ago
Risk Assessment

The static analysis of getwid-megamenu v1.0.7 reveals an excellent security posture regarding direct code vulnerabilities. The absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and the presence of 100% output escaping are strong indicators of secure coding practices. Furthermore, the plugin exhibits no apparent attack surface through AJAX, REST API, shortcodes, or cron events, and lacks any identified taint flows. This suggests the codebase is well-hardened against common attack vectors that exploit direct user input manipulation or access to sensitive system functions.

However, the vulnerability history presents a significant concern. The plugin has one known CVE, classified as medium severity, and related to Cross-site Scripting. While this vulnerability is listed as 'currently unpatched: 0,' the presence of a past vulnerability, especially one with a recent discovery date, necessitates vigilance. It indicates that despite current efforts, the plugin has had exploitable flaws in the past, and future vulnerabilities cannot be ruled out. The strength in static analysis is undermined by the historical evidence of past security weaknesses.

Key Concerns

  • 1 Medium severity CVE found
  • Potential for undiscovered vulnerabilities
Vulnerabilities
1

Navigation Block with Mega Menu Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-48258medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mega Menu Block <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 19, 2025 Patched in 1.0.7 (10d)
Code Analysis
Analyzed Mar 16, 2026

Navigation Block with Mega Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped22 total outputs
Attack Surface

Navigation Block with Mega Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitincludes\BlockRegister.php:11
actionwp_enqueue_scriptsincludes\BlockRegister.php:12
Maintenance & Trust

Navigation Block with Mega Menu Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 16, 2025
PHP min version5.6
Downloads30K

Community Trust

Rating70/100
Number of ratings13
Active installs1K
Developer Profile

Navigation Block with Mega Menu Developer Profile

jetmonsters

33 plugins · 326K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
193 days
View full developer profile
Detection Fingerprints

How We Detect Navigation Block with Mega Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/getwid-megamenu/build/index.js/wp-content/plugins/getwid-megamenu/build/index.css/wp-content/plugins/getwid-megamenu/build/style-index.css/wp-content/plugins/getwid-megamenu/build/frontend.js
Script Paths
/wp-content/plugins/getwid-megamenu/build/index.js/wp-content/plugins/getwid-megamenu/build/frontend.js
Version Parameters
getwid-megamenu/build/index.js?ver=getwid-megamenu/build/index.css?ver=getwid-megamenu/build/style-index.css?ver=getwid-megamenu/build/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-getwid-megamenu-megamenuwp-block-getwid-megamenu-megamenu-itemwp-block-getwid-megamenu-plain-menuwp-block-getwid-megamenu-plain-menu-item
Data Attributes
data-block="getwid/megamenu"data-block="getwid/megamenu-item"data-block="getwid/plain-menu"data-block="getwid/plain-menu-item"
JS Globals
window.getwid_megamenu_block_editor_data
FAQ

Frequently Asked Questions about Navigation Block with Mega Menu