
Menu Backup & Restore + Import/Export Security & Risk Analysis
wordpress.org/plugins/menu-backup-restoreProtect WordPress menus with automatic backups, one-click restore, and import/export. Transfer menus between sites with ease.
Is Menu Backup & Restore + Import/Export Safe to Use in 2026?
Generally Safe
Score 100/100Menu Backup & Restore + Import/Export has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "menu-backup-restore" plugin v1.1.2 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and having a high percentage of properly escaped outputs. The plugin also implements a reasonable number of nonce and capability checks, suggesting an awareness of common WordPress security mechanisms. Furthermore, the absence of known vulnerabilities and CVEs in its history is a strong indicator of prior security diligence.
However, a significant concern arises from the analysis of its attack surface and taint flows. The plugin exposes a single AJAX handler that lacks any authentication checks. While the total number of entry points is small, this unprotected handler represents a direct avenue for potential abuse if it can be triggered externally. The taint analysis reveals two flows with unsanitized paths, which, although not classified as critical or high severity, still warrant attention as they indicate potential pathways for malicious data to enter the application without proper sanitization. The presence of file operations, even if only one, combined with an unprotected entry point, could be a vector for manipulation if not carefully handled.
In conclusion, the plugin's strengths lie in its secure database interactions and output handling, along with a clean vulnerability history. The primary weakness is the unprotected AJAX handler, which, coupled with unsanitized taint flows, creates a notable risk. While the severity of the taint flows is not currently rated high, this combination of factors requires attention. The plugin's overall security is decent, but the unprotected AJAX entry point is a clear area for improvement to enhance its robustness.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths
Menu Backup & Restore + Import/Export Security Vulnerabilities
Menu Backup & Restore + Import/Export Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Menu Backup & Restore + Import/Export Attack Surface
AJAX Handlers 1
WordPress Hooks 20
Maintenance & Trust
Menu Backup & Restore + Import/Export Maintenance & Trust
Maintenance Signals
Community Trust
Menu Backup & Restore + Import/Export Alternatives
Export Import Menus
export-import-menus
A plugin that lets you export and import your WordPress menus in our own website under Appearance section to Export/Import Menus.
One Menu Export Import
one-menu-export-import
Easily export and import your WordPress menus with a modern, user-friendly interface. Perfect for backups, migrations, or cloning menus between sites.
Extensions Keep – Save, install and share your plugins with a single click
extensions-keep
Extensions Keep: Streamline Your WordPress Plugin Management
All-in-One WP Migration and Backup
all-in-one-wp-migration
Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate, backup, and restore your WordPress site with one click.
Customizer Backup & Reset
customizer-reset-by-wpzoom
Reset theme customizations made via WordPress Customizer with backup, export, and import features.
Menu Backup & Restore + Import/Export Developer Profile
1 plugin · 300 total installs
How We Detect Menu Backup & Restore + Import/Export
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/menu-backup-restore/assets/js/settings.js/wp-content/plugins/menu-backup-restore/assets/js/settings.jsmenu-backup-restore/assets/js/settings.js?ver=HTML / DOM Fingerprints
cm_mbrSettings