
Menu Buttons Security & Risk Analysis
wordpress.org/plugins/menu-buttonsAdd buttons to your menu.
Is Menu Buttons Safe to Use in 2026?
Generally Safe
Score 85/100Menu Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "menu-buttons" plugin v1.0 exhibits a strong security posture based on the provided static analysis. The absence of any entry points like AJAX handlers, REST API routes, or shortcodes significantly limits the attack surface. Furthermore, the code demonstrates excellent practice by exclusively using prepared statements for all SQL queries, mitigating the risk of SQL injection vulnerabilities. The lack of dangerous functions, file operations, and external HTTP requests further reinforces this positive assessment.
However, a critical concern arises from the complete lack of output escaping. With 30 total outputs identified and 0% properly escaped, this presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data rendered directly to the page without proper sanitization can be exploited by attackers to inject malicious scripts. Additionally, the absence of nonce checks and capability checks on the identified (though zero) entry points, while less immediately impactful given the current attack surface, represents a missed opportunity for robust authorization and could become a risk if the plugin evolves to include more interactive features.
The vulnerability history being completely clean is a positive indicator of past development diligence. However, the potential for XSS due to unescaped output remains the most pressing security concern for this version of the plugin. Developers should prioritize addressing the output escaping issue to achieve a more secure state.
Key Concerns
- 0% of outputs properly escaped
- 0 capability checks on entry points
- 0 nonce checks on entry points
Menu Buttons Security Vulnerabilities
Menu Buttons Code Analysis
Output Escaping
Menu Buttons Attack Surface
WordPress Hooks 4
Maintenance & Trust
Menu Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Menu Buttons Alternatives
Sticky Buttons – Floating Buttons Builder
sticky-buttons
Increase user engagement by incorporating sticky buttons that highlight relevant information on your website.
Button Generator – Easily Create Custom Buttons with Icons and Analytics
button-generation
Design and display custom buttons anywhere on your site. Add floating or inline buttons with icons, advanced targeting, and built-in analytics.
Floating Button – Easily Create Sticky, Fixed & Floating Buttons
floating-button
Floating Buttons let you easily create sticky, fixed, and floating action buttons
Bubble Menu – Floating Button Menu with Sticky Navigation
bubble-menu
Create interactive floating bubble menus to enhance site navigation and boost user engagement effortlessly.
Custom Scrollable Button – My B21 Cards
custom-scrollable-button-my-b21-cards
A simple and easy-to-use custom horizontal scrolling button solution for your WordPress site.
Menu Buttons Developer Profile
6 plugins · 630 total installs
How We Detect Menu Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
js/mb-colorpicker.jsHTML / DOM Fingerprints
my-color-field