Ollie Menu Designer Security & Risk Analysis

wordpress.org/plugins/ollie-menu-designer

Create custom dropdown & mobile menus using WordPress blocks. Design rich, responsive navigation with any block content in the block editor.

3K active installs v0.2.8 PHP 7.4+ WP 6.5+ Updated Mar 13, 2026
blockdropdown-menumega-menumobile-menunavigation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Ollie Menu Designer Safe to Use in 2026?

Generally Safe

Score 100/100

Ollie Menu Designer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The ollie-menu-designer plugin v0.2.8 exhibits a generally strong security posture based on the provided static analysis. The absence of critical vulnerabilities in taint analysis, the consistent use of prepared statements for SQL queries, and the presence of nonce and capability checks are positive indicators. Furthermore, the plugin has a clean vulnerability history with no known CVEs, suggesting a commitment to security by the developers or a lack of identified weaknesses in past versions. The limited attack surface, with only one AJAX handler and no REST API routes or shortcodes, also reduces the potential for exploitation.

However, a notable concern arises from the output escaping. With 68% of outputs properly escaped, there's a significant portion (32%) that remains unescaped. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is reflected in these unescaped output contexts. While the attack surface is small and the existing security checks are good, the unescaped output is the primary area of risk identified in this analysis. The lack of file operations and external HTTP requests further bolsters its security, but the XSS risk needs careful consideration.

In conclusion, ollie-menu-designer v0.2.8 appears to be a relatively secure plugin with a clean track record and good foundational security practices. The main weakness lies in the incomplete output escaping, which presents a potential XSS vector. Addressing this issue would significantly improve the plugin's overall security profile. The limited attack surface and lack of other critical code signals are significant strengths.

Key Concerns

  • Unescaped output (32% of outputs)
Vulnerabilities
None known

Ollie Menu Designer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Ollie Menu Designer Release Timeline

v0.2.8Current
v0.2.7
v0.2.6
v0.2.5
v0.2.4
v0.2.3
v0.2.2
v0.2.1
v0.2.0
v0.1.9
v0.1.8
v0.1.7
Code Analysis
Analyzed Mar 16, 2026

Ollie Menu Designer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
13 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

68% escaped19 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
menu_designer_handle_preview (includes\omd-preview.php:14)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Ollie Menu Designer Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_omd_dismiss_ollie_pro_noticeollie-menu-designer.php:171
WordPress Hooks 11
actioninitincludes\omd-mobile-menu-filter.php:306
filterrender_blockincludes\omd-mobile-menu-filter.php:307
actionwp_enqueue_scriptsincludes\omd-mobile-menu-filter.php:308
actiontemplate_redirectincludes\omd-preview.php:12
actionwp_footerincludes\omd-preview.php:49
actioninitollie-menu-designer.php:31
actioninitollie-menu-designer.php:46
actionadmin_headollie-menu-designer.php:74
filterdefault_wp_template_part_areasollie-menu-designer.php:101
actionplugins_loadedollie-menu-designer.php:103
actionadmin_noticesollie-menu-designer.php:153
Maintenance & Trust

Ollie Menu Designer Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 13, 2026
PHP min version7.4
Downloads27K

Community Trust

Rating100/100
Number of ratings7
Active installs3K
Developer Profile

Ollie Menu Designer Developer Profile

Mike McAlister

2 plugins · 7K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ollie Menu Designer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ollie-menu-designer/build/blocks/mega-menu/index.asset.php
Script Paths
/wp-content/plugins/ollie-menu-designer/build/index.js
Version Parameters
ollie-menu-designer/build/index.js?ver=ollie-menu-designer/build/blocks/mega-menu/index.asset.php

HTML / DOM Fingerprints

CSS Classes
omd-ollie-pro-notice
Data Attributes
data-mobile-menu-slugdata-mobile-menu-background-colordata-custom-mobile-menu-background-colordata-mobile-icon-background-colordata-custom-mobile-icon-background-colordata-mobile-icon-color+3 more
JS Globals
window.menuDesignerData
FAQ

Frequently Asked Questions about Ollie Menu Designer