Navgoco Vertical Multilevel Slide Menu Security & Risk Analysis

wordpress.org/plugins/navgoco-menu

This plugin adds the Navgoco Vertical Menu to chosen WordPress menus. It is a vertical multi-level slide menu.

100 active installs v1.1.0 PHP + WP 4.0+ Updated Dec 9, 2016
menumulti-levelvertical
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Navgoco Vertical Multilevel Slide Menu Safe to Use in 2026?

Generally Safe

Score 85/100

Navgoco Vertical Multilevel Slide Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The navgoco-menu v1.1.0 plugin presents a generally good security posture based on the provided static analysis. The absence of any discovered CVEs, combined with the fact that all SQL queries utilize prepared statements and there are no recorded vulnerability types, suggests a history of secure development. The limited attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events, further contributes to its security. However, a significant concern arises from the low percentage of properly escaped output (38%). This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied or dynamic data might be rendered directly in the browser without adequate sanitization. While the plugin demonstrates strengths in its lack of external dependencies and file operations, and its single capability check implies some level of access control, the unescaped output is a critical weakness that overshadows these positives. The absence of taint analysis findings is positive, but it does not negate the clear risk identified by the output escaping analysis.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Navgoco Vertical Multilevel Slide Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Navgoco Vertical Multilevel Slide Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
5 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped13 total outputs
Attack Surface

Navgoco Vertical Multilevel Slide Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadednavgoco-menu.php:37
actionwp_enqueue_scriptsnavgoco-menu.php:104
actionadmin_initnavgoco-menu.php:179
actionadmin_menunavgoco-menu.php:375
Maintenance & Trust

Navgoco Vertical Multilevel Slide Menu Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedDec 9, 2016
PHP min version
Downloads7K

Community Trust

Rating80/100
Number of ratings5
Active installs100
Developer Profile

Navgoco Vertical Multilevel Slide Menu Developer Profile

neilgee

8 plugins · 9K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
396 days
View full developer profile
Detection Fingerprints

How We Detect Navgoco Vertical Multilevel Slide Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/navgoco-menu/js/jquery.navgoco.js/wp-content/plugins/navgoco-menu/js/jquery.cookie.min.js/wp-content/plugins/navgoco-menu/css/navgoco.css/wp-content/plugins/navgoco-menu/js/navgoco-init.js
Script Paths
/wp-content/plugins/navgoco-menu/js/jquery.navgoco.js/wp-content/plugins/navgoco-menu/js/jquery.cookie.min.js/wp-content/plugins/navgoco-menu/js/navgoco-init.js
Version Parameters
jquery.navgoco.js?ver=jquery.cookie.min.js?ver=navgoco.css?ver=navgoco-init.js?ver=

HTML / DOM Fingerprints

JS Globals
navgocoVars
FAQ

Frequently Asked Questions about Navgoco Vertical Multilevel Slide Menu