Menu Obfuscator Security & Risk Analysis

wordpress.org/plugins/menu-obfuscator

Menu Obfuscator is a simple plugin that provides a intuitive interface to hide specific areas or menus on your Wordpress admin, for each user individu …

60 active installs v1.0 PHP + WP 3.0.1+ Updated Mar 10, 2020
hide-menumenunavigationsubmenu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Menu Obfuscator Safe to Use in 2026?

Generally Safe

Score 85/100

Menu Obfuscator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The menu-obfuscator v1.0 plugin exhibits a generally positive security posture based on the static analysis. The absence of any identified attack surface points, dangerous functions, raw SQL queries, file operations, or external HTTP requests is commendable. Furthermore, the plugin demonstrates good practices by using prepared statements for all its SQL queries. However, a significant concern arises from the very low percentage (14%) of properly escaped output. This indicates a high potential for cross-site scripting (XSS) vulnerabilities, as unsanitized user-supplied data could be directly rendered in the browser.

Despite the clean taint analysis and a complete lack of recorded vulnerability history, the output escaping issue represents a tangible risk. The plugin's vulnerability history being entirely clean, coupled with no critical taint flows, suggests a history of good security practices or a lack of significant scrutiny. Nevertheless, the unescaped output is a clear weakness that could be exploited. The plugin's strengths lie in its limited attack surface and secure data handling for SQL, but its primary weakness is the widespread lack of output sanitization, which demands immediate attention.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

Menu Obfuscator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Menu Obfuscator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
12
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

14% escaped14 total outputs
Attack Surface

Menu Obfuscator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initmenu-obfuscator.php:42
actionadmin_initmenu-obfuscator.php:43
actionadmin_headmenu-obfuscator.php:45
actionadmin_headmenu-obfuscator.php:46
actionadmin_menumenu-obfuscator.php:47
Maintenance & Trust

Menu Obfuscator Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedMar 10, 2020
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs60
Developer Profile

Menu Obfuscator Developer Profile

Jose da Silva

1 plugin · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Menu Obfuscator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/menu-obfuscator/assets/js/swmo.js/wp-content/plugins/menu-obfuscator/assets/css/swmo.css
Script Paths
/wp-content/plugins/menu-obfuscator/assets/js/swmo.js
Version Parameters
swmo_js?v1.0

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Menu Obfuscator