Iks Menu – WordPress Category Accordion Menu & FAQs Security & Risk Analysis

wordpress.org/plugins/iks-menu

Super customizable WordPress plugin for displaying custom menus, taxonomy/category terms and FAQs as accordion menu (with images support).

10K active installs v1.12.7 PHP 5.4+ WP 4.4.0+ Updated Jan 15, 2026
accordion-menucategory-widgetfaqs-listtaxonomies-menuwoocommerce-menu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Iks Menu – WordPress Category Accordion Menu & FAQs Safe to Use in 2026?

Generally Safe

Score 100/100

Iks Menu – WordPress Category Accordion Menu & FAQs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin "iks-menu" v1.12.7 exhibits a generally positive security posture based on the provided static analysis. The absence of any identified CVEs and the plugin's clean vulnerability history suggest a history of secure development and maintenance. Furthermore, the code analysis reveals no direct SQL injection vulnerabilities due to the exclusive use of prepared statements, no critical or high severity taint flows, and a lack of dangerous function usage. The plugin also demonstrates some good security practices with the presence of nonce and capability checks, and a single external HTTP request which is a minimal attack vector.

However, there are areas for improvement. A significant concern is the relatively low percentage of properly escaped output (34%), indicating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully in all output contexts. While the attack surface is currently reported as zero, this relies on the accuracy of the analysis and could change with future updates. The presence of a bundled library, Freemius v1.0, warrants attention, as outdated bundled libraries can introduce known vulnerabilities, though the specific version's security status isn't detailed here.

In conclusion, "iks-menu" v1.12.7 appears to be a reasonably secure plugin with a strong history. The primary weakness lies in output escaping. Addressing the insufficient output escaping should be the priority to mitigate potential XSS risks and further solidify its security.

Key Concerns

  • Insufficient output escaping (34% proper)
  • Bundled library (Freemius v1.0) may be outdated
Vulnerabilities
None known

Iks Menu – WordPress Category Accordion Menu & FAQs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Iks Menu – WordPress Category Accordion Menu & FAQs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
39
20 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

34% escaped59 total outputs
Attack Surface

Iks Menu – WordPress Category Accordion Menu & FAQs Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
actionafter_uninstalliks-menu.php:71
actionplugins_loadediks-menu.php:120
actionwidgets_initiks-menu.php:130
actioninitincludes\AdminLocal.php:59
actionrest_api_initincludes\API\AdminAPI.php:51
actioninitincludes\core\Admin.php:87
actionadmin_headincludes\core\Admin.php:90
actionadmin_enqueue_scriptsincludes\core\Admin.php:91
actionadmin_enqueue_scriptsincludes\core\Admin.php:92
actionadmin_menuincludes\core\Admin.php:95
actionwp_headincludes\core\FrontendInitializer.php:47
actionwp_enqueue_scriptsincludes\core\FrontendInitializer.php:48
actionwp_enqueue_scriptsincludes\core\FrontendInitializer.php:49
actioninitincludes\images\AdminMenusImprover.php:52
actionadmin_enqueue_scriptsincludes\images\AdminMenusImprover.php:54
filterwp_edit_nav_menu_walkerincludes\images\AdminMenusImprover.php:65
filterwp_nav_menu_item_custom_fieldsincludes\images\AdminMenusImprover.php:70
filtermanage_nav-menus_columnsincludes\images\AdminMenusImprover.php:71
actionwp_update_nav_menu_itemincludes\images\AdminMenusImprover.php:72
actioncreated_termincludes\images\AdminTaxonomiesImprover.php:74
actionedit_termincludes\images\AdminTaxonomiesImprover.php:75
actionadmin_enqueue_scriptsincludes\images\AdminTaxonomiesImprover.php:77
Maintenance & Trust

Iks Menu – WordPress Category Accordion Menu & FAQs Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 15, 2026
PHP min version5.4
Downloads132K

Community Trust

Rating100/100
Number of ratings27
Active installs10K
Developer Profile

Iks Menu – WordPress Category Accordion Menu & FAQs Developer Profile

Iks Studio

1 plugin · 10K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Iks Menu – WordPress Category Accordion Menu & FAQs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/iks-menu/assets/js/public.js/wp-content/plugins/iks-menu/assets/css/public.css
Version Parameters
iks-menu/assets/js/public.js?ver=iks-menu/assets/css/public.css?ver=

HTML / DOM Fingerprints

CSS Classes
iks-menu-containeriks-menu-naviks-menu-itemiks-menu-linkiks-menu-submenuiks-menu-trigger
HTML Comments
<!-- Iks Menu -->
Data Attributes
data-iksm-iddata-iksm-menu-slug
JS Globals
IksMenu
REST Endpoints
/wp-json/iks-menu/v1/menus
Shortcode Output
[iks_menu
FAQ

Frequently Asked Questions about Iks Menu – WordPress Category Accordion Menu & FAQs