
Menu In Menu Security & Risk Analysis
wordpress.org/plugins/menu-in-menuPlace one Custom Menu inside another Custom Menu
Is Menu In Menu Safe to Use in 2026?
Generally Safe
Score 85/100Menu In Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "menu-in-menu" plugin version 1.0.0 demonstrates a generally strong security posture in several key areas. The absence of any known CVEs and a clean vulnerability history are significant positives, suggesting a well-maintained and likely secure plugin. Furthermore, the code analysis reveals no dangerous functions, no file operations, and no external HTTP requests, all of which reduce potential attack vectors. The fact that all SQL queries use prepared statements is also excellent practice.
However, there are critical concerns. A complete lack of output escaping on all identified outputs is a major red flag. This means that any data rendered to the user could potentially be exploited through cross-site scripting (XSS) vulnerabilities. The complete absence of nonce and capability checks, even though the attack surface is currently zero, implies a lack of fundamental security protections that could become problematic if the plugin's functionality evolves or new entry points are introduced. While the plugin currently has no entry points, this could change in future versions, leaving it vulnerable if these basic checks aren't implemented.
In conclusion, while the "menu-in-menu" plugin has a good track record and avoids common pitfalls like raw SQL, the critical oversight in output escaping and the complete lack of authorization checks for any potential future entry points present significant risks. The plugin is not recommended for use without immediate remediation of these issues.
Key Concerns
- All identified outputs are unescaped
- No nonce checks implemented
- No capability checks implemented
Menu In Menu Security Vulnerabilities
Menu In Menu Code Analysis
Output Escaping
Menu In Menu Attack Surface
WordPress Hooks 6
Maintenance & Trust
Menu In Menu Maintenance & Trust
Maintenance Signals
Community Trust
Menu In Menu Alternatives
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Admin Menu Editor
admin-menu-editor
Lets you edit the WordPress admin menu. You can re-order, hide or rename menus, add custom menus and more.
Happy Addons for Elementor
happy-elementor-addons
HappyAddons for Elementor-Get Header Footer, Single Post, Archive Page, Megamenu, Slider Builder & 143 Elementor Widgets.
Max Mega Menu
megamenu
An easy to use mega menu plugin. Written the WordPress way.
Menu In Menu Developer Profile
3 plugins · 3K total installs
How We Detect Menu In Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/menu-in-menu/menu-in-menu.phpmenu-in-menu/menu-in-menu.php?ver=1.0.0HTML / DOM Fingerprints
<!-- v1.1.0 initial release -->data-mim-menu-id[menu-in-menu]