
HT Menu – WordPress Mega Menu Builder for Elementor Security & Risk Analysis
wordpress.org/plugins/ht-menu-liteHT Menu is a Elementor page builder addon to create menu and mega menu for WordPress websites. It allows to add Elementor templates to build coloumn a …
Is HT Menu – WordPress Mega Menu Builder for Elementor Safe to Use in 2026?
Generally Safe
Score 100/100HT Menu – WordPress Mega Menu Builder for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The ht-menu-lite v1.2.5 plugin exhibits a mixed security posture. While it demonstrates strengths in areas like exclusively using prepared statements for SQL queries and implementing nonce and capability checks on its entry points, several concerns warrant attention. The presence of a dangerous `create_function` function is a significant code signal risk, as this function is deprecated and can be exploited in various ways if not handled with extreme care. Furthermore, the taint analysis revealing two flows with unsanitized paths, although not classified as critical or high severity, indicates a potential for unexpected data handling and possible injection vectors if these paths involve user-supplied input. The vulnerability history, specifically the medium-severity CVE, although currently patched, suggests that the plugin has had past security weaknesses. The lack of unpatched CVEs is positive, but the pattern of past vulnerabilities, including CSRF, suggests a need for continued vigilance in code review and security best practices. Overall, while the plugin has good foundations, the identified code signals and taint analysis results present areas of potential risk that could be exploited.
Key Concerns
- Dangerous function detected (`create_function`)
- Taint flows with unsanitized paths
- Medium severity vulnerability in history
- Output escaping only 52% properly escaped
HT Menu – WordPress Mega Menu Builder for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
HT Menu <= 1.2.1 - Cross-Site Request Forgery via plugin_activation
HT Menu – WordPress Mega Menu Builder for Elementor Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
HT Menu – WordPress Mega Menu Builder for Elementor Attack Surface
AJAX Handlers 3
WordPress Hooks 27
Maintenance & Trust
HT Menu – WordPress Mega Menu Builder for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
HT Menu – WordPress Mega Menu Builder for Elementor Alternatives
RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg
rt-mega-menu
RT Mega Menu is a powerful WordPress mega menu plugin that lets you build advanced, responsive mega menus using Elementor or the Gutenberg block edito …
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Happy Addons for Elementor
happy-elementor-addons
HappyAddons for Elementor-Get Header Footer, Single Post, Archive Page, Megamenu, Slider Builder & 143 Elementor Widgets.
HT Mega Addons for Elementor – Elementor Widgets & Template Builder
ht-mega-for-elementor
Elementor addon offering 135+ widgets — Mega Menu, Ready Templates, Page Builder, Slider, Gallery, Post Grid, AI Writer & more.
HT Menu – WordPress Mega Menu Builder for Elementor Developer Profile
14 plugins · 16K total installs
How We Detect HT Menu – WordPress Mega Menu Builder for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ht-menu-lite/include/admin/assets/css/admin_optionspanel.cssht-menu-lite/include/admin/assets/css/admin_optionspanel.css?ver=1.2.5HTML / DOM Fingerprints
htmegamenu-adminelement_section_titleHTMEGA_MENU_VERSIONHTMEGA_MENU_PL_URL