
GT Push Menu Lite Security & Risk Analysis
wordpress.org/plugins/gt-push-menu-liteEasy to use and configure, multilevel offcanvas mobile navigation menu plugin.
Is GT Push Menu Lite Safe to Use in 2026?
Generally Safe
Score 85/100GT Push Menu Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gt-push-menu-lite" plugin v1.2.1 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs and a clean vulnerability history is a significant strength. Furthermore, the lack of any identified taint flows, particularly critical or high severity ones, suggests that the plugin does not appear to be processing user-supplied data in a way that could lead to common web vulnerabilities. The plugin also appears to have a small attack surface, with no registered AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without proper authentication or permission checks.
However, there are areas of concern indicated by the static analysis. The presence of the `unserialize` function, especially without clear evidence of nonce checks or strict input validation, poses a potential risk. The usage of `unserialize` on untrusted input can lead to remote code execution vulnerabilities. Additionally, the low percentage of properly escaped output (20%) and the limited capability checks (1) suggest that there might be opportunities for cross-site scripting (XSS) or information disclosure vulnerabilities, particularly if the outputs are used in contexts where they are interpreted by the browser without sanitization.
In conclusion, while the plugin's vulnerability history is exemplary and its attack surface is minimal, the identified code signals regarding `unserialize` usage and insufficient output escaping warrant attention. Addressing these specific weaknesses would further strengthen the plugin's security.
Key Concerns
- Dangerous function 'unserialize' used without checks
- Low percentage of properly escaped output
- No nonce checks on entry points
- Limited capability checks
GT Push Menu Lite Security Vulnerabilities
GT Push Menu Lite Release Timeline
GT Push Menu Lite Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
GT Push Menu Lite Attack Surface
WordPress Hooks 6
Maintenance & Trust
GT Push Menu Lite Maintenance & Trust
Maintenance Signals
Community Trust
GT Push Menu Lite Alternatives
Max Mega Menu
megamenu
An easy to use mega menu plugin. Written the WordPress way.
WP Mobile Bottom Menu
mobile-bottom-menu-for-wp
Smooth Navigation for Mobile. Create an Eye-Catching Sticky Bottom Menu with Limitless Customization Options.
Ollie Menu Designer
ollie-menu-designer
Create custom dropdown & mobile menus using WordPress blocks. Design rich, responsive navigation with any block content in the block editor.
Offcanvas Mobile Menu
offcanvas-menu
Best plugin to display beautiful fully customizable and responsive Offcanvas Mobile Menu or Wordrpess Hamberger Mobile Menu.
Mobile Menu Builder for WordPress
mobile-menu-builder
WordPress Mobile Menu Builder plugin is specially designed for mobiles. It is easy to use, customizable, and is highly flexible.
GT Push Menu Lite Developer Profile
1 plugin · 10 total installs
How We Detect GT Push Menu Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gt-push-menu-lite/css/colpick.css/wp-content/plugins/gt-push-menu-lite/js/colpick.js/wp-content/plugins/gt-push-menu-lite/js/pusher.color.min.js/wp-content/plugins/gt-push-menu-lite/js/admin.js/wp-content/plugins/gt-push-menu-lite/css/admin.css/wp-content/plugins/gt-push-menu-lite/js/gtpm.js/wp-content/plugins/gt-push-menu-lite/js/modernizr.custom.js/wp-content/plugins/gt-push-menu-lite/js/jquery.nicescroll.js+4 more/wp-content/plugins/gt-push-menu-lite/js/colpick.js/wp-content/plugins/gt-push-menu-lite/js/pusher.color.min.js/wp-content/plugins/gt-push-menu-lite/js/admin.js/wp-content/plugins/gt-push-menu-lite/js/gtpm.js/wp-content/plugins/gt-push-menu-lite/js/modernizr.custom.js/wp-content/plugins/gt-push-menu-lite/js/jquery.nicescroll.js+1 moregt-push-menu-lite/css/colpick.css?ver=gt-push-menu-lite/js/colpick.js?ver=gt-push-menu-lite/js/pusher.color.min.js?ver=gt-push-menu-lite/js/admin.js?ver=gt-push-menu-lite/css/admin.css?ver=gt-push-menu-lite/js/gtpm.js?ver=gt-push-menu-lite/js/modernizr.custom.js?ver=gt-push-menu-lite/js/jquery.nicescroll.js?ver=gt-push-menu-lite/css/gt-push-menu.css?ts=gt-push-menu-lite/css/gt-push-menu-icons.css?ver=gt-push-menu-lite/css/style.css?ver=gt-push-menu-lite/js/jquery.tap.min.js?ts=HTML / DOM Fingerprints
gtpm_containergtpm_overlaygtpm_navgtpm_nav_wrappergtpm_maingtpm_mobile_menu_trigger<!-- Generated by GT Push Menu Lite --><!-- widget area: GT Push Menu Right Sidebar -->data-gtpm-colordata-gtpm-overlapdata-gtpm-menustyleGTPMGTPM_VERSIONgtpm