Orbisius Quick Nav Security & Risk Analysis

wordpress.org/plugins/orbisius-quick-nav

Switch quickly between pages, posts, or any other custom post types.

40 active installs v1.0.8 PHP + WP 3.0.0+ Updated May 29, 2017
orbisiussidebarwidgetwidgetswp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Orbisius Quick Nav Safe to Use in 2026?

Generally Safe

Score 85/100

Orbisius Quick Nav has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'orbisius-quick-nav' plugin version 1.0.8 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs and the lack of critical or high-severity issues in taint analysis are positive indicators. Furthermore, the plugin has no reported vulnerabilities in its history, suggesting a history of secure development or timely patching by maintainers.

However, there are notable areas of concern within the static analysis. The most significant is the presence of a single SQL query that does not utilize prepared statements, increasing the risk of SQL injection vulnerabilities. Additionally, a substantial portion of the plugin's output (87%) is not properly escaped, which opens the door to cross-site scripting (XSS) vulnerabilities. The complete lack of nonce and capability checks across all entry points also presents a significant security gap, particularly if any functionalities were to be added in the future that could be leveraged by unauthenticated or unauthorized users.

In conclusion, while the plugin has a clean vulnerability history and no identified critical flaws, the identified code-level weaknesses in SQL handling and output escaping, coupled with a lack of robust authentication checks, present tangible risks. These issues should be addressed to improve the overall security of the plugin.

Key Concerns

  • SQL queries without prepared statements
  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Orbisius Quick Nav Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Orbisius Quick Nav Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
47
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

13% escaped54 total outputs
Attack Surface

Orbisius Quick Nav Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninitorbisius-quick-nav.php:29
actionwp_footerorbisius-quick-nav.php:30
actionadmin_initorbisius-quick-nav.php:33
actionadmin_menuorbisius-quick-nav.php:34
filterorbisius_quick_nav_dropdown_item_labelorbisius-quick-nav.php:94
filterplugin_action_linksorbisius-quick-nav.php:311
actionall_admin_noticesorbisius-quick-nav.php:343
actionadmin_footerorbisius-quick-nav.php:348
actionadmin_enqueue_scriptsorbisius-quick-nav.php:349
Maintenance & Trust

Orbisius Quick Nav Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedMay 29, 2017
PHP min version
Downloads4K

Community Trust

Rating84/100
Number of ratings6
Active installs40
Developer Profile

Orbisius Quick Nav Developer Profile

Svetoslav Marinov

26 plugins · 12K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
722 days
View full developer profile
Detection Fingerprints

How We Detect Orbisius Quick Nav

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/orbisius-quick-nav/css/style.css/wp-content/plugins/orbisius-quick-nav/js/orbisius-quick-nav.js
Script Paths
//cdnjs.cloudflare.com/ajax/libs/chosen/1.4.2/chosen.jquery.min.js
Version Parameters
orbisius-quick-nav/css/style.css?ver=orbisius-quick-nav/js/orbisius-quick-nav.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- /orbisius_quick_nav_dropdown_container -->
Data Attributes
name="orb_quick_nav_select"id="orb_quick_nav_select_page_id"id="orb_quick_nav_select_post_id"
JS Globals
orbisius_quick_nav_cfgorbisius_quick_nav_admin_inline_js
FAQ

Frequently Asked Questions about Orbisius Quick Nav