Menu Organizer Security & Risk Analysis

wordpress.org/plugins/menu-organizer

A simple plugin to organize your admin menus

60 active installs v1.0.1 PHP 7.2+ WP 5.2+ Updated Mar 5, 2025
admin-menucustomize-menudashboard-customizationgroup-menumenu-organizer
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Menu Organizer Safe to Use in 2026?

Generally Safe

Score 92/100

Menu Organizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "menu-organizer" plugin v1.0.1 presents a generally positive security posture based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, or external HTTP requests is a strong indicator of good development practices. Furthermore, the fact that 100% of SQL queries use prepared statements and all output is properly escaped significantly mitigates common web application vulnerabilities. The presence of nonce checks, while limited, is also a positive sign. The lack of any recorded CVEs, both historical and currently unpatched, further reinforces this impression of a secure plugin.

However, a significant concern arises from the complete lack of capability checks. While nonce checks help prevent cross-site request forgery, they do not verify user permissions. This means that any entry points, if they were to exist and were not properly secured by nonces, could potentially be accessed by any authenticated user, regardless of their role. The minimal attack surface (0 entry points) currently negates this specific risk, but it represents a fundamental gap in security controls. The plugin's current minimal attack surface is a strength, but the absence of capability checks is a critical weakness that could become a significant vulnerability if the attack surface were to expand in future versions.

Key Concerns

  • Missing capability checks on all entry points
Vulnerabilities
None known

Menu Organizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Menu Organizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
49 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped49 total outputs
Attack Surface

Menu Organizer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterparent_fileincludes\class-main.php:14
actionadmin_initincludes\class-main.php:15
actionadmin_initincludes\class-settings.php:13
actionadmin_menuincludes\class-settings.php:14
actionadmin_enqueue_scriptsincludes\class-settings.php:15
Maintenance & Trust

Menu Organizer Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 5, 2025
PHP min version7.2
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

Menu Organizer Developer Profile

iamraymund

2 plugins · 70 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Menu Organizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/menu-organizer/assets/css/global.css/wp-content/plugins/menu-organizer/assets/css/nano.min.css/wp-content/plugins/menu-organizer/assets/js/pickr.min.js/wp-content/plugins/menu-organizer/assets/css/dashicons-picker.css/wp-content/plugins/menu-organizer/assets/js/dashicons-picker.js/wp-content/plugins/menu-organizer/assets/css/settings.css/wp-content/plugins/menu-organizer/assets/css/admin-menu.css/wp-content/plugins/menu-organizer/assets/js/settings.js+1 more
Script Paths
/wp-content/plugins/menu-organizer/assets/js/pickr.min.js/wp-content/plugins/menu-organizer/assets/js/dashicons-picker.js/wp-content/plugins/menu-organizer/assets/js/settings.js/wp-content/plugins/menu-organizer/assets/js/admin-menu.js
Version Parameters
menu-organizer/assets/css/global.css?ver=menu-organizer/assets/css/nano.min.css?ver=menu-organizer/assets/js/pickr.min.js?ver=menu-organizer/assets/css/dashicons-picker.css?ver=menu-organizer/assets/js/dashicons-picker.js?ver=menu-organizer/assets/css/settings.css?ver=menu-organizer/assets/css/admin-menu.css?ver=menu-organizer/assets/js/settings.js?ver=menu-organizer/assets/js/admin-menu.js?ver=

HTML / DOM Fingerprints

CSS Classes
admin-menu-settings-formaction-buttonsfloat-leftfloat-right
Data Attributes
data-option-group="meor_plugin"data-option-name="meor_plugin_option"
FAQ

Frequently Asked Questions about Menu Organizer