Menus Security & Risk Analysis

wordpress.org/plugins/menus

A Multisite Network plugin to toggle administration menus for the entire network of sites.

30 active installs v4.6 PHP + WP 3.7.1+ Updated Aug 8, 2016
admin-menusadministration-menusmenusmultisitetoggle-admin-menus
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Menus Safe to Use in 2026?

Generally Safe

Score 85/100

Menus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The static analysis of the 'menus' plugin v4.6 reveals an exceptionally strong security posture. The complete absence of attack surface points such as AJAX handlers, REST API routes, shortcodes, and cron events, coupled with a lack of dangerous functions and file operations, significantly reduces the plugin's exposure to common web vulnerabilities. Furthermore, the code demonstrates robust security practices with 100% of SQL queries utilizing prepared statements and all output being properly escaped. The presence of 64 capability checks further reinforces the commitment to secure access controls. Taint analysis shows no identified flows, indicating a lack of potential data injection or manipulation issues within the analyzed code paths.

The vulnerability history for this plugin is also remarkably clean, with zero recorded CVEs across all severity levels. This indicates a history of secure development and proactive patching if any issues have arisen in the past. The lack of any recorded vulnerabilities suggests the developers are either highly diligent or the plugin's functionality is inherently simple and less prone to exploitable flaws. Overall, the 'menus' plugin v4.6 appears to be a highly secure and well-maintained WordPress plugin, with no immediate security concerns identified based on the provided data.

Vulnerabilities
None known

Menus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Menus Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Menus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
64
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Menus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
filtermu_menu_itemsds_wp3_menus.php:28
actionwpmu_optionsds_wp3_menus.php:29
actionadmin_menuds_wp3_menus.php:30
actionjetpack_admin_menuds_wp3_menus.php:31
actionadmin_menuds_wp3_menus.php:32
filteradmin_bar_menuds_wp3_menus.php:33
actionadmin_page_access_deniedds_wp3_menus.php:34
actionadmin_initds_wp3_menus.php:37
filterinitds_wp3_menus.php:38
actionload-customize.phpds_wp3_menus.php:49
filtermap_meta_capds_wp3_menus.php:57
Maintenance & Trust

Menus Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedAug 8, 2016
PHP min version
Downloads22K

Community Trust

Rating100/100
Number of ratings6
Active installs30
Developer Profile

Menus Developer Profile

David Sader

6 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Menus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Menus