Menu Icons by ThemeIsle Security & Risk Analysis
wordpress.org/plugins/menu-iconsSpice up your navigation menus with pretty icons, easily.
Is Menu Icons by ThemeIsle Safe to Use in 2026?
Generally Safe
Score 98/100Menu Icons by ThemeIsle has a strong security track record. Known vulnerabilities have been patched promptly.
The 'menu-icons' plugin v0.13.21 exhibits a generally strong security posture in its static analysis, with no critical or high-severity code signals like dangerous functions, raw SQL queries, or unsanitized file operations. The plugin demonstrates good practices in output escaping, with 93% of outputs properly handled, and utilizes prepared statements for all SQL queries. The limited attack surface, consisting of a single AJAX handler without explicit authentication checks, is a point of minor concern. However, the presence of 5 nonce checks, though not directly tied to the AJAX handler in the provided data, suggests an awareness of input validation, but the absence of capability checks for the AJAX handler is a notable weakness. The vulnerability history reveals a past of two medium-severity Cross-Site Scripting (XSS) vulnerabilities, with the most recent one patched. While there are currently no unpatched vulnerabilities, this history indicates a recurring susceptibility to XSS, suggesting that input sanitization might still require rigorous scrutiny, especially for any user-supplied data that could potentially reach output functions.
Key Concerns
- AJAX handler without auth checks
- Two past medium XSS vulnerabilities
- No capability checks on AJAX handler
Menu Icons by ThemeIsle Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Menu Icons by ThemeIsle <= 0.13.20 - Authenticated (Author+) Stored Cross-Site Scripting
Menu Icons by ThemeIsle <= 0.13.13 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload
Menu Icons by ThemeIsle Code Analysis
Output Escaping
Data Flow Analysis
Menu Icons by ThemeIsle Attack Surface
AJAX Handlers 1
WordPress Hooks 31
Maintenance & Trust
Menu Icons by ThemeIsle Maintenance & Trust
Maintenance Signals
Community Trust
Menu Icons by ThemeIsle Alternatives
Menu Image, Icons made easy
menu-image
Adds an image or icon in the menu items. You can choose the position of the image (after, before, above, below) or even hide the menu item title.
Easy Menu Icons – Awesome Menu Icons
easy-menu-icons
The Easy Menu Icons Plugin for WordPress menu icon plugin where can decoration your menu item with different types icon.
Material UI Menu Icons – Nifty Menu Options
nifty-menu-options
Adds beautiful icons to your WordPress menu items. More menu item options are coming soon!
The Menu: Custom mobile navigation with icons
the-menu
Create beautiful mobile navigation menus with custom icons, role-based visibility, and extensive style options for your WordPress site.
sTRASHo
strasho
sTRASHo is a smart and easy way to delete your menu items.
Menu Icons by ThemeIsle Developer Profile
37 plugins · 2.2M total installs
How We Detect Menu Icons by ThemeIsle
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/menu-icons/css/dashboard-notice.cssmenu-icons/css/dashboard-notice.css?ver=HTML / DOM Fingerprints
menu-icon-dashboard-notice