
Menu Image, Icons made easy Security & Risk Analysis
wordpress.org/plugins/menu-imageAdds an image or icon in the menu items. You can choose the position of the image (after, before, above, below) or even hide the menu item title.
Is Menu Image, Icons made easy Safe to Use in 2026?
Generally Safe
Score 99/100Menu Image, Icons made easy has a strong security track record. Known vulnerabilities have been patched promptly.
The "menu-image" plugin v3.13 presents a mixed security posture. While it demonstrates good practices such as 100% use of prepared statements for SQL queries and a significant percentage of properly escaped output, there are notable areas of concern. The presence of an unprotected AJAX handler significantly increases the attack surface, providing an entry point for unauthenticated malicious actions.
Taint analysis indicates a potential for unsanitized paths, although thankfully no critical or high severity flows were identified in this version. The plugin's vulnerability history is concerning, with two known medium severity Cross-Site Scripting (XSS) vulnerabilities, the last of which was identified relatively recently in December 2023. Although currently unpatched CVEs are zero, this pattern suggests a tendency towards issues that could expose users to XSS attacks if not carefully addressed.
In conclusion, the plugin benefits from secure database interactions and reasonable output sanitization. However, the unprotected AJAX handler and past XSS vulnerabilities represent the most significant risks. Continued vigilance and prompt patching of any newly discovered vulnerabilities are crucial for maintaining a secure environment.
Key Concerns
- AJAX handler without authentication
- Flows with unsanitized paths
- Past medium severity XSS vulnerabilities (2)
- Output escaping is only 65% proper
Menu Image, Icons made easy Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Menu Image, Icons made easy <= 3.10 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings
Menu Image, Icons made easy <= 3.0.7 - Authenticated Cross-Site Scripting
Menu Image, Icons made easy Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Menu Image, Icons made easy Attack Surface
AJAX Handlers 5
WordPress Hooks 23
Maintenance & Trust
Menu Image, Icons made easy Maintenance & Trust
Maintenance Signals
Community Trust
Menu Image, Icons made easy Alternatives
Menu Icons by ThemeIsle
menu-icons
Spice up your navigation menus with pretty icons, easily.
Easy Menu Icons – Awesome Menu Icons
easy-menu-icons
The Easy Menu Icons Plugin for WordPress menu icon plugin where can decoration your menu item with different types icon.
Material UI Menu Icons – Nifty Menu Options
nifty-menu-options
Adds beautiful icons to your WordPress menu items. More menu item options are coming soon!
Bellows Accordion Menu
bellows-accordion-menu
A flexible and robust accordion menu plugin
Nav Menu Images
nav-menu-images
Display image as a menu item content.
Menu Image, Icons made easy Developer Profile
4 plugins · 180K total installs
How We Detect Menu Image, Icons made easy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/menu-image/css/menu-image.css/wp-content/plugins/menu-image/css/menu-image-admin.css/wp-content/plugins/menu-image/js/menu-image.js/wp-content/plugins/menu-image/js/menu-image-admin.js/wp-content/plugins/menu-image/js/menu-image.js/wp-content/plugins/menu-image/js/menu-image-admin.jsmenu-image/css/menu-image.css?ver=menu-image/css/menu-image-admin.css?ver=menu-image/js/menu-image.js?ver=menu-image/js/menu-image-admin.js?ver=HTML / DOM Fingerprints
menu-image-item-settings-contentmenu-image-modal-headermenu-image-close-overlaymenu-image-icon-settingsmenu-image-button-settingsmenu-image-notifications-settingsdata-menu-iddata-menu-item-idmenuImage/wp-json/menu-image/v1/settings