ITG Admin Hover Menus Security & Risk Analysis

wordpress.org/plugins/itg-admin-hover-menus

Shows on hover sub menus of recent posts, pages and custom post types.

10 active installs v1.2.1 PHP 5.4+ WP 4.0+ Updated Mar 9, 2026
adminhovermenuproductivitytooltip
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ITG Admin Hover Menus Safe to Use in 2026?

Generally Safe

Score 100/100

ITG Admin Hover Menus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 25d ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'itg-admin-hover-menus' plugin version 1.2.1 exhibits a strong security posture. The static analysis reveals no identified attack surface in terms of AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code signals indicate a lack of dangerous functions, all SQL queries utilize prepared statements, and output is consistently and properly escaped. There are also no file operations or external HTTP requests detected, and crucially, no nonce or capability checks are identified as missing. The taint analysis also found no issues with unsanitized paths across any severity levels. The vulnerability history further reinforces this positive assessment, with zero known CVEs, either historical or current, across all severity levels. This lack of historical vulnerabilities suggests a commitment to secure coding practices or a lack of targeted exploitation. Overall, this plugin appears to be well-developed with a minimal attack surface and robust security implementations. The primary weakness, though minor in the context of found issues, is the complete absence of nonce and capability checks, which, while not leading to identified vulnerabilities in this version, represent a potential area for improvement in defensive coding, especially if the plugin were to introduce new features or integrations in the future. However, given the current findings, the risk associated with this plugin is very low.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

ITG Admin Hover Menus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ITG Admin Hover Menus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

ITG Admin Hover Menus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menuitg-admin-hover-menus.php:10
Maintenance & Trust

ITG Admin Hover Menus Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version5.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ITG Admin Hover Menus Developer Profile

itgoldman

2 plugins · 10 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ITG Admin Hover Menus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about ITG Admin Hover Menus