
Navigation Du Lapin Blanc Security & Risk Analysis
wordpress.org/plugins/navigation-du-lapin-blancThis plugin provides integrated navigation for your website. Use WordPress as a CMS for your website and think in navigation terms (main, sub etc.)
Is Navigation Du Lapin Blanc Safe to Use in 2026?
Use With Caution
Score 64/100Navigation Du Lapin Blanc has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "navigation-du-lapin-blanc" plugin v1.1.1 presents a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, raw SQL queries, file operations, and external HTTP requests. Furthermore, there are no identified taint flows with unsanitized paths, and the attack surface is small with no unprotected entry points like AJAX handlers or REST API routes without proper callbacks.
However, significant concerns arise from the static analysis regarding output escaping. With 100% of outputs not being properly escaped, this plugin is highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on its shortcodes is another critical oversight, potentially allowing unauthorized actions or data manipulation if these shortcodes are used in conjunction with user-provided input.
The plugin's vulnerability history further exacerbates these concerns. It has a known medium severity CVE related to XSS that is currently unpatched. This, combined with the code analysis indicating a lack of output escaping, strongly suggests that the previous XSS vulnerability might still be present or that similar vulnerabilities could easily be introduced. While the plugin avoids some common pitfalls, the lack of output escaping and the unpatched XSS vulnerability represent substantial security risks.
Key Concerns
- Unpatched CVE (Medium severity XSS)
- Output escaping missing on all outputs
- Missing nonce checks on shortcodes
- Missing capability checks on shortcodes
Navigation Du Lapin Blanc Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Navigation Du Lapin Blanc <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Navigation Du Lapin Blanc Code Analysis
Output Escaping
Navigation Du Lapin Blanc Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
Navigation Du Lapin Blanc Maintenance & Trust
Maintenance Signals
Community Trust
Navigation Du Lapin Blanc Alternatives
CMS Navigation
cms-navigation
Out-of-the-box support for full CMS navigation in your WordPress site including drop down menus, breadcrumbs trail and sidebar navigation.
Max Mega Menu
megamenu
An easy to use mega menu plugin. Written the WordPress way.
Table of Contents Plus
table-of-contents-plus
A powerful yet user friendly plugin that automatically creates a table of contents. Can also output a sitemap listing all pages and categories.
Menu Icons by ThemeIsle
menu-icons
Spice up your navigation menus with pretty icons, easily.
Menu Image, Icons made easy
menu-image
Adds an image or icon in the menu items. You can choose the position of the image (after, before, above, below) or even hide the menu item title.
Navigation Du Lapin Blanc Developer Profile
4 plugins · 10K total installs
How We Detect Navigation Du Lapin Blanc
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/navigation-du-lapin-blanc/css/navigation-du-lapin-blanc.css/wp-content/plugins/navigation-du-lapin-blanc/js/navigation-du-lapin-blanc.js/wp-content/plugins/navigation-du-lapin-blanc/js/navigation-du-lapin-blanc.jsnavigation-du-lapin-blanc/style.css?ver=navigation-du-lapin-blanc.js?ver=HTML / DOM Fingerprints
bjoerne_navigationbjoerne_sub_navigationbjoerne_current_pathbjoerne_selected_itembjoerne_selected_item_parentbjoerne_sitemap<!-- NAVIGATION DU LAPIN BLANC start --><!-- NAVIGATION DU LAPIN BLANC end --><!-- bjoerne_sitemap start --><!-- bjoerne_sitemap end -->+2 moredata-bjoerne-page-typedata-bjoerne-category-iddata-bjoerne-category-namedata-bjoerne-urlbjoerne_root_nodesbjoerne_current_nodebjoerne_current_pathbjoerne_navigation_nodesbjoerne_name_resolversbjoerne_default_name_resolver+2 more[bjoerne_sitemap][bjoerne_navigation_menu]