Menu Item Duplicator Security & Risk Analysis

wordpress.org/plugins/menu-item-duplicator

Allow you to duplicate menu items and their sub-elements in Appearance > Menus

2K active installs v1.0.2 PHP + WP 4.0+ Updated Oct 16, 2024
duplicatemenunavigation
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Menu Item Duplicator Safe to Use in 2026?

Generally Safe

Score 92/100

Menu Item Duplicator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "menu-item-duplicator" v1.0.2 plugin exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified entry points, including AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces its attack surface. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions, all SQL queries using prepared statements, and all output being properly escaped. The lack of file operations, external HTTP requests, and crucially, the absence of nonce and capability checks, while a concern in principle for entry points, is mitigated here by the fact that there are no observable entry points to exploit. The clean taint analysis with zero unsanitized paths reinforces this positive assessment.

The vulnerability history is equally impressive, showing zero known CVEs of any severity. This lack of historical vulnerabilities suggests either a highly secure development process, minimal exposure, or a combination of both. The absence of recent vulnerabilities further solidifies this perception of a well-maintained and secure plugin. However, the complete absence of capability checks across all potential (though currently non-existent) entry points represents a theoretical weakness that could become a concern if the plugin were to evolve and introduce new ways for users to interact with it without proper authorization checks.

In conclusion, the "menu-item-duplicator" v1.0.2 plugin currently presents a very low security risk. Its design has effectively minimized the attack surface, and the code itself appears to follow secure coding practices. The lack of historical vulnerabilities is a strong indicator of its stability. The primary, albeit theoretical, concern lies in the complete lack of capability checks, which could become a point of failure if the plugin's functionality expands without addressing this.

Key Concerns

  • Missing capability checks on potential entry points
Vulnerabilities
None known

Menu Item Duplicator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Menu Item Duplicator Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Menu Item Duplicator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Menu Item Duplicator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_initmenu-item-duplicator.php:32
actionadmin_enqueue_scriptsmenu-item-duplicator.php:63
Maintenance & Trust

Menu Item Duplicator Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 16, 2024
PHP min version
Downloads17K

Community Trust

Rating76/100
Number of ratings13
Active installs2K
Developer Profile

Menu Item Duplicator Developer Profile

mathieuhays

1 plugin · 2K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Menu Item Duplicator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/menu-item-duplicator/dist/menu-item-duplicator.min.js/wp-content/plugins/menu-item-duplicator/src/menu-item-duplicator.js
Script Paths
dist/menu-item-duplicator.min.jssrc/menu-item-duplicator.js
Version Parameters
menu-item-duplicator/dist/menu-item-duplicator.min.js?ver=menu-item-duplicator/src/menu-item-duplicator.js?ver=

HTML / DOM Fingerprints

JS Globals
menuItemDuplicator
FAQ

Frequently Asked Questions about Menu Item Duplicator