HHD Flatsome Vertical Menu Security & Risk Analysis

wordpress.org/plugins/hhd-flatsome-vertical-menu

Vertical Menu for Flatsome theme.

10 active installs v2.0.0 PHP 5.4+ WP 5.4+ Updated Jan 8, 2021
flatsomehhd-flatsome-vertical-menuvertical-menu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HHD Flatsome Vertical Menu Safe to Use in 2026?

Generally Safe

Score 85/100

HHD Flatsome Vertical Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The hhd-flatsome-vertical-menu plugin v2.0.0 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong indicator of secure coding practices. Furthermore, the lack of any recorded vulnerabilities, CVEs, or critical taint flows suggests a history of responsible development and maintenance.

However, there are areas for improvement. The plugin has two shortcodes which are not explicitly detailed in terms of their input handling or output escaping beyond the general statistic. While the overall output escaping is at 67%, this means a significant portion (33%) of outputs may not be properly sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. The complete absence of nonce checks and capability checks, while not directly leading to deductions based on the provided metrics (as there are no AJAX or REST API endpoints analyzed as unprotected), represents a potential weakness if functionality were to be added that is sensitive to CSRF or requires specific user roles.

In conclusion, the plugin is currently in a strong security position with no known vulnerabilities or obvious critical flaws. The primary concern lies in the unescaped output percentage and the potential for future issues arising from the lack of nonce and capability checks. Addressing the output escaping and considering these checks for any future feature development would further solidify its security.

Key Concerns

  • Significant percentage of unescaped output
Vulnerabilities
None known

HHD Flatsome Vertical Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

HHD Flatsome Vertical Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped21 total outputs
Attack Surface

HHD Flatsome Vertical Menu Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[ux_submenu_link] shortcodes.php:112
[ux_vertical_menu] shortcodes.php:269
WordPress Hooks 3
actionux_builder_setupbuilder\builder.php:7
actionplugins_loadedhhd-flatsome-vertical-menu.php:78
actionwp_enqueue_scriptsshortcodes.php:120
Maintenance & Trust

HHD Flatsome Vertical Menu Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedJan 8, 2021
PHP min version5.4
Downloads1K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

HHD Flatsome Vertical Menu Developer Profile

Huu Ha

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HHD Flatsome Vertical Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hhd-flatsome-vertical-menu/assets/css/huuhadev-vertical-menu.css/wp-content/plugins/hhd-flatsome-vertical-menu/assets/js/huuhadev-vertical-menu.js
Script Paths
/wp-content/plugins/hhd-flatsome-vertical-menu/assets/js/huuhadev-vertical-menu.js
Version Parameters
huuhadev-vertical-menu-stylehuuhadev-vertical-menu-script

HTML / DOM Fingerprints

CSS Classes
ux-menu-linkux-menu-link--activenav-dropdownnav-dropdown-full-widthhuuhadev-vertical-menu
Data Attributes
data-block_iddata-design
Shortcode Output
[block id="ux_submenu_link
FAQ

Frequently Asked Questions about HHD Flatsome Vertical Menu