
Local Navigation Extended Security & Risk Analysis
wordpress.org/plugins/local-navigation-extendedThis simple widget uses the wp_list_pages() to output a local navigation menu.
Is Local Navigation Extended Safe to Use in 2026?
Generally Safe
Score 85/100Local Navigation Extended has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "local-navigation-extended" plugin version 0.1 exhibits a very limited attack surface, with no detected AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the static analysis found no dangerous functions, file operations, or external HTTP requests, and all SQL queries utilize prepared statements. This indicates a strong adherence to secure coding practices in these areas.
However, a significant concern arises from the complete absence of output escaping for all detected outputs. This means that any data rendered by the plugin could potentially be vulnerable to cross-site scripting (XSS) attacks if it originates from untrusted user input. The lack of nonce and capability checks on entry points (though there are none detected) would also be a major concern if such entry points existed. The plugin's vulnerability history is clean, which is a positive sign, but given the present code analysis findings, it's possible that vulnerabilities have simply not been discovered or reported yet.
In conclusion, while the plugin demonstrates a commendable effort in minimizing its attack surface and securing its data interactions, the critical oversight in output escaping presents a tangible risk. The absence of past vulnerabilities should not overshadow this current, identifiable security flaw. Addressing the output escaping issue should be the immediate priority.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
Local Navigation Extended Security Vulnerabilities
Local Navigation Extended Code Analysis
Output Escaping
Local Navigation Extended Attack Surface
WordPress Hooks 1
Maintenance & Trust
Local Navigation Extended Maintenance & Trust
Maintenance Signals
Community Trust
Local Navigation Extended Alternatives
Local Navigation Widget
local-navigation-widget
This simple widget uses the wp_list_pages() to output a local navigation menu.
CleanCodeNZ Exclude Pages Plugin
cleancode-exclude-pages
This is a plugin to hide pages from navigation and/or search results using custom fields, parent and child pages are supported too
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Admin Menu Editor
admin-menu-editor
Lets you edit the WordPress admin menu. You can re-order, hide or rename menus, add custom menus and more.
Local Navigation Extended Developer Profile
3 plugins · 120 total installs
How We Detect Local Navigation Extended
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/local-navigation-extended/css/local-navigation-extended.css/wp-content/plugins/local-navigation-extended/js/local-navigation-extended.js/wp-content/plugins/local-navigation-extended/js/local-navigation-extended.jslocal-navigation-extended/css/local-navigation-extended.css?ver=local-navigation-extended/js/local-navigation-extended.js?ver=HTML / DOM Fingerprints
local-navigation-extended-widgetlocal_navigation_extended_params