
Menu Description Security & Risk Analysis
wordpress.org/plugins/menu-descriptionAdd the description from menu items when the item is display
Is Menu Description Safe to Use in 2026?
Generally Safe
Score 100/100Menu Description has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "menu-description" v1.0.4 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, file operations, external HTTP requests, and the complete reliance on prepared statements for SQL queries are all excellent practices. Furthermore, all output is properly escaped, mitigating common cross-site scripting (XSS) vulnerabilities. The attack surface is minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, all these potential entry points (even though none exist) are indicated as protected. The plugin also has no recorded vulnerability history, suggesting a history of secure development and maintenance.
While the static analysis reveals no immediate vulnerabilities or concerning code patterns, the lack of observed taint flows is noted. It's possible that the plugin's functionality is extremely limited, or that the taint analysis was not comprehensive enough to detect potential issues in more complex scenarios. The absence of nonce checks and capability checks, while not a direct risk given the zero attack surface, could become a concern if functionality were to be added in the future without proper security considerations. The overall assessment is that the plugin is currently secure and well-developed, with no known issues or significant red flags in its existing codebase.
Menu Description Security Vulnerabilities
Menu Description Code Analysis
Output Escaping
Menu Description Attack Surface
WordPress Hooks 6
Maintenance & Trust
Menu Description Maintenance & Trust
Maintenance Signals
Community Trust
Menu Description Alternatives
LC Disable CDN
lc-disable-cdn
Disable CDN rewriting for the Live Composer Editor
SOGO Add Script to Individual Pages Header Footer
oh-add-script-header-footer
Simple plugin to add script to header and footer for individual pages & posts
TC Custom JavaScript
tc-custom-javascript
Add custom JavaScript to your site from a professional editor in the WordPress admin.
Jquery Validation For Contact Form 7
jquery-validation-for-contact-form-7
New standard of advance validation for Contact Form 7.
Better WordPress Minify
bwp-minify
Allows you to combine and minify your CSS and JS files to improve page load time.
Menu Description Developer Profile
11 plugins · 390 total installs
How We Detect Menu Description
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
menu-item-descriptionname="show-menu-description"id="show-menu-description"