OT Flatsome Vertical Menu Security & Risk Analysis

wordpress.org/plugins/ot-flatsome-vertical-menu

Vertical Menu for Flatsome Woocommerce theme.

10K active installs v1.2.3 PHP + WP 4.0+ Updated Jun 17, 2020
flatsomevertical-menu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OT Flatsome Vertical Menu Safe to Use in 2026?

Generally Safe

Score 85/100

OT Flatsome Vertical Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of "ot-flatsome-vertical-menu" v1.2.3 reveals a strong security posture with no identified entry points for attacks such as AJAX handlers, REST API routes, shortcodes, or cron events. The code demonstrates good practices by avoiding dangerous functions, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests. Furthermore, the absence of taint analysis findings indicates no evident vulnerabilities related to unsanitized data flows.

While the code analysis is overwhelmingly positive, a notable concern arises from the lack of nonce checks and capability checks. This suggests that even if entry points were discovered, they might not be adequately protected against common WordPress vulnerabilities like Cross-Site Request Forgery (CSRF) or unauthorized access by less privileged users. The moderate percentage of properly escaped output (83%) also leaves a small window for potential Cross-Site Scripting (XSS) vulnerabilities, although the absence of taint findings mitigates this risk considerably.

The plugin's vulnerability history is completely clean, with no known CVEs or past issues. This, combined with the positive static analysis results, suggests a well-maintained and secure plugin. However, the absence of nonce and capability checks is a persistent weakness that should be addressed to further strengthen its security, even in the absence of immediate threats.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • 17% of output not properly escaped
Vulnerabilities
None known

OT Flatsome Vertical Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

OT Flatsome Vertical Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped12 total outputs
Attack Surface

OT Flatsome Vertical Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuincludes\class-ot-vertical-menu-settings.php:23
actionadmin_initincludes\class-ot-vertical-menu-settings.php:24
filterbody_classincludes\functions.php:26
filterflatsome_header_elementot-flatsome-vertical-menu.php:26
actionafter_setup_themeot-flatsome-vertical-menu.php:27
actionwp_enqueue_scriptsot-flatsome-vertical-menu.php:28
actionflatsome_header_elementsot-flatsome-vertical-menu.php:30
Maintenance & Trust

OT Flatsome Vertical Menu Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 17, 2020
PHP min version
Downloads79K

Community Trust

Rating94/100
Number of ratings22
Active installs10K
Developer Profile

OT Flatsome Vertical Menu Developer Profile

thinhbg59

4 plugins · 10K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OT Flatsome Vertical Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ot-flatsome-vertical-menu/assets/css/style.css/wp-content/plugins/ot-flatsome-vertical-menu/assets/vendor/superfish/hoverIntent.js/wp-content/plugins/ot-flatsome-vertical-menu/assets/vendor/superfish/superfish.min.js/wp-content/plugins/ot-flatsome-vertical-menu/assets/js/ot-vertical-menu.min.js
Script Paths
/wp-content/plugins/ot-flatsome-vertical-menu/assets/vendor/superfish/hoverIntent.js/wp-content/plugins/ot-flatsome-vertical-menu/assets/vendor/superfish/superfish.min.js/wp-content/plugins/ot-flatsome-vertical-menu/assets/js/ot-vertical-menu.min.js
Version Parameters
ot-flatsome-vertical-menu/assets/css/style.css?ver=ot-flatsome-vertical-menu/assets/vendor/superfish/hoverIntent.js?ver=ot-flatsome-vertical-menu/assets/vendor/superfish/superfish.min.js?ver=ot-flatsome-vertical-menu/assets/js/ot-vertical-menu.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
ot-vm-clickot-vm-hoveris-megasf-menusf-vertical
JS Globals
OT_FL_VERTICAL_MENU_VERSIONOT_FL_VERTICAL_MENU_DIROT_FL_VERTICAL_MENU_URI
Shortcode Output
<div id="mega-menu-wrap"<div id="mega-menu-title"<i class="icon-menu"></i>
FAQ

Frequently Asked Questions about OT Flatsome Vertical Menu