
Menu Override Security & Risk Analysis
wordpress.org/plugins/menu-overrideOverride the menu in use on a page level when your template only supports one.
Is Menu Override Safe to Use in 2026?
Generally Safe
Score 85/100Menu Override has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'menu-override' plugin version 0.4.1 presents a generally positive security posture based on the provided static analysis. The plugin demonstrates good security practices by having no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-member attack surface that is entirely protected. Furthermore, the code signals indicate a lack of dangerous functions, raw SQL queries, file operations, and external HTTP requests, all of which are excellent indicators of secure coding. The presence of a nonce check and a capability check also adds a layer of defense.
However, a significant concern arises from the output escaping. With 6 total outputs and only 33% properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied data, if processed and displayed without proper sanitization, could be exploited to inject malicious scripts into web pages. The absence of any identified taint flows or known historical vulnerabilities is a positive sign, suggesting the plugin has not been a target of past exploits or a source of severe security flaws. Despite the strong foundation in preventing common attack vectors, the unescaped output is a critical weakness that needs immediate attention.
In conclusion, while 'menu-override' v0.4.1 exhibits commendable practices in minimizing its attack surface and avoiding risky code patterns, the significantly low rate of proper output escaping poses a notable security risk. The lack of historical vulnerabilities is encouraging, but it doesn't negate the immediate threat posed by the XSS potential. Addressing the output escaping is paramount to improving the plugin's overall security.
Key Concerns
- Low rate of proper output escaping
Menu Override Security Vulnerabilities
Menu Override Code Analysis
Output Escaping
Menu Override Attack Surface
WordPress Hooks 3
Maintenance & Trust
Menu Override Maintenance & Trust
Maintenance Signals
Community Trust
Menu Override Alternatives
F12 Floating Menu, sticky menu for WordPress
f12-floating-menu
Easily add unlimited floating/sticky menus to your Website. The F12 Floating Menu comes with an easy-to-use interface, allowing you to have the full c …
AGCA – Custom Dashboard & Login Page
ag-custom-admin
CHANGE: admin menu, login page, admin bar, dashboard widgets, custom colors, custom CSS & JS, logo & images
Custom Menu Wizard Widget
custom-menu-wizard
Show branches or levels of your menu in a widget, or in content using a shortcode, with full customisation.
Zen Menu Logic
zen-menu-logic
Zen Menu Logic allows the user to select any of several custom menus to appear on a per page basis.
Custom Menu
custom-menu
This plugin allows you to display a custom menu that you've created in your theme's "Menus" section in a post or page.
Menu Override Developer Profile
2 plugins · 100 total installs
How We Detect Menu Override
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
menuOverrideSelectionmo_menu_location_