MenuMax – Digital Restaurant Menus Security & Risk Analysis

wordpress.org/plugins/menumax-digital-restaurant-menus

Create stunning, mobile-responsive digital restaurant menus with drag-and-drop builder, WooCommerce integration, and multi-currency support.

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Nov 23, 2025
digital-menufood-menumenu-builderrestaurant-menuwoocommerce-menu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MenuMax – Digital Restaurant Menus Safe to Use in 2026?

Generally Safe

Score 100/100

MenuMax – Digital Restaurant Menus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "menumax-digital-restaurant-menus" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by having no AJAX handlers, REST API routes, or cron events exposed, and no known vulnerabilities in its history. The code also utilizes prepared statements for all SQL queries and has a high percentage of properly escaped output, indicating a focus on preventing common web vulnerabilities. The presence of nonce and capability checks further strengthens its defenses.

However, there is one specific area of concern: the presence of a single shortcode, which represents an entry point into the plugin. While the static analysis indicates no unprotected entry points overall, shortcodes can sometimes be a vector for vulnerabilities if not handled with extreme care. The taint analysis, though limited in scope with only two flows analyzed, found no unsanitized paths, which is a positive sign. The absence of dangerous functions and external HTTP requests is also commendable.

Overall, this plugin appears to be well-developed with security in mind, especially given its clean vulnerability history and proactive use of security best practices in its code. The single shortcode remains a minor point of attention, but without further analysis of its implementation, it's difficult to assign a significant risk. The lack of any historical vulnerabilities further bolsters confidence in its current security.

Key Concerns

  • Single shortcode as an entry point
Vulnerabilities
None known

MenuMax – Digital Restaurant Menus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

MenuMax – Digital Restaurant Menus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
32 escaped
Nonce Checks
5
Capability Checks
4
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped37 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
crm_handle_menu_import (includes\menu-settings.php:175)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MenuMax – Digital Restaurant Menus Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[crm_menu] includes\menu-shortcodes.php:105
WordPress Hooks 19
actionadd_meta_boxes_crm_menuincludes\menu-admin-ui.php:16
actionadmin_enqueue_scriptsincludes\menu-admin-ui.php:76
actionsave_post_crm_menuincludes\menu-admin-ui.php:105
actionadmin_enqueue_scriptsincludes\menu-admin-ui.php:128
actioninitincludes\menu-post-types.php:38
actionadd_meta_boxesincludes\menu-post-types.php:52
actionsave_post_crm_menu_itemincludes\menu-post-types.php:74
actionadd_meta_boxesincludes\menu-post-types.php:88
actionsave_post_crm_menu_itemincludes\menu-post-types.php:134
actionadmin_enqueue_scriptsincludes\menu-post-types.php:156
filtermanage_crm_menu_posts_columnsincludes\menu-post-types.php:165
actionmanage_crm_menu_posts_custom_columnincludes\menu-post-types.php:172
actionadmin_menuincludes\menu-settings.php:5
actionadmin_menuincludes\menu-settings.php:20
actionadmin_initincludes\menu-settings.php:45
actionadmin_menuincludes\menu-settings.php:86
actionadmin_post_crm_export_menusincludes\menu-settings.php:122
actionadmin_post_crm_import_menusincludes\menu-settings.php:174
actionwp_enqueue_scriptsmenumax-digital-restaurant-menus.php:24
Maintenance & Trust

MenuMax – Digital Restaurant Menus Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 23, 2025
PHP min version7.4
Downloads178

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

MenuMax – Digital Restaurant Menus Developer Profile

Polar Line Services LLC

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MenuMax – Digital Restaurant Menus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/menumax-digital-restaurant-menus/css/crm-menu-styles.css
Version Parameters
crm-menu-stylescrm-admin-js

HTML / DOM Fingerprints

CSS Classes
crm-menu-item
Data Attributes
data-id
FAQ

Frequently Asked Questions about MenuMax – Digital Restaurant Menus