
Merge Menus Security & Risk Analysis
wordpress.org/plugins/merge-menusQuickly add the elements of 1 menu on to another
Is Merge Menus Safe to Use in 2026?
Generally Safe
Score 85/100Merge Menus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The merge-menus plugin v1.1.3 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and raw SQL queries is commendable. The high percentage of properly escaped output further reduces the risk of cross-site scripting vulnerabilities. The presence of capability checks on the single AJAX handler, coupled with zero AJAX handlers lacking authentication, indicates a good understanding of secure WordPress development practices for entry points.
While the analysis reveals a clean slate regarding vulnerability history and taint flows, it's important to note the absence of nonce checks on the AJAX handler. Although the handler has capability checks, the lack of nonce verification is a potential weakness that could be exploited in certain scenarios, especially if the plugin handles sensitive data or actions. This is the primary area of concern in an otherwise robustly developed plugin.
In conclusion, merge-menus v1.1.3 is a secure plugin with excellent coding practices. The lack of historical vulnerabilities and critical code signals is highly positive. The only notable weakness identified is the missing nonce check on its sole AJAX handler, which, while not a critical flaw in isolation due to the presence of capability checks, represents a deviation from best practices for protecting AJAX endpoints.
Key Concerns
- Missing nonce check on AJAX handler
Merge Menus Security Vulnerabilities
Merge Menus Code Analysis
Output Escaping
Merge Menus Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Merge Menus Maintenance & Trust
Maintenance Signals
Community Trust
Merge Menus Alternatives
Ultimate Order Combination
woo-ultimate-order-combination
Merge and manage WooCommerce orders with ease.
APH Merge Scripts
aph-merge-scripts
Merge and minify CSS & javascript files into one file. Easy to use. Support remote file - Javascript & CSS files hosted on other server or CDN
Merge PDF with Cross Service Solutions integration
merge-pdf
A WordPress plugin to merge PDF files using the service of XSS (Cross Service Solutions) Pte Ltd.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Merge Menus Developer Profile
4 plugins · 540 total installs
How We Detect Merge Menus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
merge-menussubmit-merge-menusid="merge-menus"id="merge-menu"id="submit-merge-menus"window.wpNavMenu/wp-json/merge-menu-get-items