Menubar Widgets Security & Risk Analysis

wordpress.org/plugins/menubar-widgets

A standard wordpress plugin that helps you add multiple widgets to navigation menu item.

100 active installs v0.1.0 PHP + WP 3.6+ Updated Mar 10, 2014
menunavigationwidgetwidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Menubar Widgets Safe to Use in 2026?

Generally Safe

Score 85/100

Menubar Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "menubar-widgets" plugin version 0.1.0 exhibits a concerning security posture despite having no known CVEs or complex attack surfaces. The static analysis reveals that 53% of output operations are not properly escaped. This is a significant concern as unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into web pages viewed by other users. While the plugin has no identified SQL queries that aren't prepared, and no direct file operations or external HTTP requests, the high percentage of unescaped output presents a clear and present danger. The taint analysis indicates two flows with unsanitized paths, which, while not classified as critical or high severity, warrant attention and suggest a potential for vulnerabilities if these paths are exposed to user input without proper sanitization. The absence of any vulnerability history is a positive sign, but it does not mitigate the risks identified in the code analysis. The plugin needs immediate attention to address the unescaped output to improve its security.

Key Concerns

  • High percentage of unescaped output
  • Flows with unsanitized paths
Vulnerabilities
None known

Menubar Widgets Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Menubar Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
47
42 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

47% escaped89 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
start_el (inc\Walker_Menubar_Widgets.class.php:9)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Menubar Widgets Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedmenubar-widgets.php:23
actionplugins_loadedmenubar-widgets.php:26
actionplugins_loadedmenubar-widgets.php:29
actionwidgets_initmenubar-widgets.php:32
actionwp_edit_nav_menu_walkermenubar-widgets.php:35
actionwalker_nav_menu_start_elmenubar-widgets.php:36
actionwp_update_nav_menu_itemmenubar-widgets.php:39
actionwidgets.phpmenubar-widgets.php:40
actionmbw_register_error_rowsmenubar-widgets.php:43
actionnav_menu_css_classmenubar-widgets.php:46
actionadmin_enqueue_scriptsmenubar-widgets.php:47
Maintenance & Trust

Menubar Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedMar 10, 2014
PHP min version
Downloads16K

Community Trust

Rating98/100
Number of ratings7
Active installs100
Developer Profile

Menubar Widgets Developer Profile

Hadi khosrojerdi

2 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Menubar Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/menubar-widgets/css/menubar-widgets-admin.css/wp-content/plugins/menubar-widgets/js/menubar-widgets-admin.js
Script Paths
/wp-content/plugins/menubar-widgets/js/menubar-widgets-admin.js
Version Parameters
menubar-widgets/css/menubar-widgets-admin.css?ver=menubar-widgets/js/menubar-widgets-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
menubar-widgetmenubar-widget-titlemenubar-widget-errormenubar-widget-error-msgmenubar-widget-error-msg-wrap
Data Attributes
data-widget-id
FAQ

Frequently Asked Questions about Menubar Widgets