Move Nav-Menu Security & Risk Analysis

wordpress.org/plugins/move-nav-menu

Moves the WordPress nav-menu item in admin to a new top level page. Out of "Appearance".

20 active installs v1.0.2 PHP + WP 4.2+ Updated Jun 8, 2015
menumovemove-navnavnav-menu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Move Nav-Menu Safe to Use in 2026?

Generally Safe

Score 85/100

Move Nav-Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "move-nav-menu" v1.0.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, unescaped outputs, file operations, external HTTP requests, or SQL queries not using prepared statements is a positive indicator. Furthermore, the plugin's attack surface is zero, with no AJAX handlers, REST API routes, shortcodes, or cron events, suggesting a minimal potential for exploitation. The vulnerability history also reflects a clean record, with no known CVEs, which is a significant strength.

However, the analysis also reveals a complete lack of security checks such as nonce checks and capability checks across all components. While the current attack surface is zero, if any entry points were to be introduced in future versions, their unprotected nature would immediately pose a significant risk. The absence of any identified taint flows is commendable, but this is in conjunction with an absence of any analyzed flows at all. This could indicate that the plugin is very simple, or that the analysis might be incomplete in terms of identifying potential interaction points.

In conclusion, "move-nav-menu" v1.0.2 appears secure in its current state due to its limited functionality and the absence of known vulnerabilities. The main area for improvement and a potential future risk lies in the implementation of robust authentication and authorization checks should the plugin evolve or its functionality expand.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Move Nav-Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Move Nav-Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Move Nav-Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menumove-nav-menu.php:60
filterparent_filemove-nav-menu.php:78
filteruser_has_capmove-nav-menu.php:93
Maintenance & Trust

Move Nav-Menu Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJun 8, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Move Nav-Menu Developer Profile

tormorten

6 plugins · 100 total installs

83
trust score
Avg Security Score
84/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Move Nav-Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Move Nav-Menu