Ozh' Admin Drop Down Menu Security & Risk Analysis

wordpress.org/plugins/ozh-admin-drop-down-menu

All admin links available in a neat horizontal drop down menu. Saves lots of screen real estate!

3K active installs v3.7.1 PHP 5.6+ WP 4.0+ Updated Jun 9, 2020
admindashboardmenumenusozh
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ozh' Admin Drop Down Menu Safe to Use in 2026?

Generally Safe

Score 85/100

Ozh' Admin Drop Down Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The ozh-admin-drop-down-menu v3.7.1 plugin exhibits a generally strong security posture based on the static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks, coupled with a complete lack of dangerous functions and file operations, significantly limits its attack surface. All SQL queries are properly prepared, and nonce checks and capability checks are present, indicating good secure coding practices in these areas. The vulnerability history is also clean, with no recorded CVEs, which suggests a well-maintained and secure codebase over time. However, a significant concern arises from the output escaping. With 96 total outputs and only 5% properly escaped, there's a high probability of cross-site scripting (XSS) vulnerabilities. Additionally, the taint analysis revealed one flow with unsanitized paths, although it was not flagged as critical or high severity, it still represents a potential for unexpected behavior or vulnerabilities if an attacker can influence the path input. These points of concern, particularly the widespread lack of output escaping, detract from an otherwise robust security profile.

Key Concerns

  • Low output escaping percentage
  • Unsanitized path flow in taint analysis
Vulnerabilities
None known

Ozh' Admin Drop Down Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ozh' Admin Drop Down Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
91
5 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

5% escaped96 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<adminmenu.css> (inc\adminmenu.css.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Ozh' Admin Drop Down Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_noticesinc\core.php:436
actionadmin_initwp_ozh_adminmenu.php:138
actionadmin_menuwp_ozh_adminmenu.php:139
actionadmin_headwp_ozh_adminmenu.php:140
actionin_admin_footerwp_ozh_adminmenu.php:141
filterozh_adminmenu_icon_ozh_admin_menuwp_ozh_adminmenu.php:143
filterin_admin_headerwp_ozh_adminmenu.php:144
Maintenance & Trust

Ozh' Admin Drop Down Menu Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 9, 2020
PHP min version5.6
Downloads873K

Community Trust

Rating98/100
Number of ratings74
Active installs3K
Developer Profile

Ozh' Admin Drop Down Menu Developer Profile

Ozh

27 plugins · 5K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ozh' Admin Drop Down Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ozh-admin-drop-down-menu/ozh-adminmenu.css/wp-content/plugins/ozh-admin-drop-down-menu/ozh-adminmenu.js/wp-content/plugins/ozh-admin-drop-down-menu/colorpicker/js/colorpicker.js/wp-content/plugins/ozh-admin-drop-down-menu/colorpicker/css/colorpicker.css/wp-content/plugins/ozh-admin-drop-down-menu/svg/icons.svg
Script Paths
/wp-content/plugins/ozh-admin-drop-down-menu/ozh-adminmenu.js
Version Parameters
ozh-admin-drop-down-menu/ozh-adminmenu.css?ver=ozh-admin-drop-down-menu/ozh-adminmenu.js?ver=ozh-admin-drop-down-menu/colorpicker/js/colorpicker.js?ver=ozh-admin-drop-down-menu/colorpicker/css/colorpicker.css?ver=

HTML / DOM Fingerprints

CSS Classes
ozh-admin-menuozh-admin-dropdown-menu
Data Attributes
data-ozh-admin-menu-init
JS Globals
ozh_admin_menu_options
FAQ

Frequently Asked Questions about Ozh' Admin Drop Down Menu