
Move Admin Menu Items Security & Risk Analysis
wordpress.org/plugins/move-admin-menu-itemsMove admin menu items to an overview menu page.
Is Move Admin Menu Items Safe to Use in 2026?
Generally Safe
Score 85/100Move Admin Menu Items has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'move-admin-menu-items' plugin, version 1.0.2, exhibits a strong security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events, meaning the plugin does not expose a direct attack surface that could be exploited. Furthermore, the code signals indicate a lack of dangerous functions, file operations, and external HTTP requests, all of which are positive security indicators. SQL queries are exclusively handled with prepared statements, and there are no recorded vulnerabilities in its history. This suggests a well-developed plugin with security as a priority.
However, a significant concern arises from the low percentage of properly escaped output (14%). While the absence of other risky elements is commendable, unescaped output can lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is ever processed and displayed without proper sanitization. This is a critical area that needs immediate attention to prevent potential security breaches. The lack of nonce checks and capability checks is also a weakness, especially if any future functionality introduces more interaction points.
In conclusion, the plugin's core design is secure with no immediate exploitable surface or historical vulnerabilities. The strength lies in its minimal attack surface and secure SQL practices. The primary weakness, and the most significant risk, is the poor output escaping, which could allow for XSS attacks. Addressing this output escaping issue should be the top priority for securing this plugin.
Key Concerns
- Low percentage of properly escaped output
- 0 Nonce checks detected
- 0 Capability checks detected
Move Admin Menu Items Security Vulnerabilities
Move Admin Menu Items Code Analysis
Output Escaping
Move Admin Menu Items Attack Surface
WordPress Hooks 6
Maintenance & Trust
Move Admin Menu Items Maintenance & Trust
Maintenance Signals
Community Trust
Move Admin Menu Items Alternatives
WP Adminify – White Label WordPress, Admin Menu Editor, Login Customizer
adminify
Transform your WordPress admin into a fully white-labeled, organized client dashboard. Customize, Dark mode, Secure, Boost productivity, and more.
Admin Tools
admin-tools
Admin Tools Helps you to get better admin for your customers. Manage your menus, plugins, Top Bar, updates and more
Admin Menu Cleaner
wp-admin-menu-wizard
Wp Admin Menu Wizard lets you hide the menu items you do not use very often.
Menu Organizer
menu-organizer
A simple plugin to organize your admin menus
WP Total Branding – Complete branding solution for WordPress
wp-total-branding
Make your WordPress truly yours. Customize, clean up, and remove default WordPress footprints, features, and more.
Move Admin Menu Items Developer Profile
1 plugin · 70 total installs
How We Detect Move Admin Menu Items
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/move-admin-menu-items/css/stb_mami-admin.cssstb_mami-admin.css?ver=HTML / DOM Fingerprints
stb_mami_settings_containerstb_mami_settings__itemstb_mami_settings__labelstb_mami_settings__menu-itemname="stb_mami_settings[stb_mami_field_menuitems][]"