
Page Category & Archive Menu Security & Risk Analysis
wordpress.org/plugins/page-category-and-archive-menuYou can embed page, category, and archive menu in your Wordperss site. You can get documentation and view demos from following site:
Is Page Category & Archive Menu Safe to Use in 2026?
Generally Safe
Score 85/100Page Category & Archive Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "page-category-and-archive-menu" plugin version 1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL queries by exclusively using prepared statements and has no recorded vulnerability history, suggesting a history of secure development or minimal exposure. It also avoids dangerous functions, file operations, and external HTTP requests, further contributing to a secure baseline.
However, significant concerns arise from the static analysis. The lack of any output escaping for all 56 identified outputs is a critical weakness, potentially leading to Cross-Site Scripting (XSS) vulnerabilities. Additionally, the taint analysis reveals two flows with unsanitized paths, which, while not currently classified as critical or high severity, indicate potential for malicious data to be processed without proper sanitization. The absence of nonce checks and capability checks on its entry points, despite having a limited attack surface of 3 shortcodes, is also a notable omission that could be exploited if these shortcodes are sensitive or handle user-controllable data.
In conclusion, while the plugin's SQL handling and vulnerability history are commendable, the pervasive lack of output escaping and the presence of unsanitized taint flows represent significant security risks that require immediate attention. The absence of capability checks on its shortcodes further adds to the potential for insecure operation. Addressing these issues would substantially improve the plugin's overall security.
Key Concerns
- All outputs are unescaped (XSS risk)
- Taint flows with unsanitized paths detected
- Missing nonce checks on entry points
- Missing capability checks on entry points
Page Category & Archive Menu Security Vulnerabilities
Page Category & Archive Menu Release Timeline
Page Category & Archive Menu Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Page Category & Archive Menu Attack Surface
Shortcodes 3
WordPress Hooks 4
Maintenance & Trust
Page Category & Archive Menu Maintenance & Trust
Maintenance Signals
Community Trust
Page Category & Archive Menu Alternatives
Category For Pages
category-for-pages
Adds categories and tags functionality for your pages.
Page Category and Tag – Add Categories and Tags to WordPress Pages
page-categories-tags
Add categories and tags to WordPress pages. Enable page category and page tag support easily.
Category Page Extender
category-page-extender
Inserts posts into pages corresponding to category. Add on plugin for Category Page by pixline.net. Requieres an active installation of Category Page …
SF Category Menu
sf-category-menu
Easy treeview menu for WordPress categories.
Categorize Pages
categorize-pages
Categorize Pages, just as you would do with Posts
Page Category & Archive Menu Developer Profile
3 plugins · 250 total installs
How We Detect Page Category & Archive Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/page-category-and-archive-menu/style.css/wp-content/plugins/page-category-and-archive-menu/linkmenu.js/wp-content/plugins/page-category-and-archive-menu/linkmenu.jspage-category-and-archive-menu/style.css?ver=HTML / DOM Fingerprints
pgcatmenupgcatmenu_listorcp_page_data_jsonorcp_cats_data_jsonorcp_arcvs_data_jsonpgcatmenu_font_sizepgcatmenu_line_spacingpgcatmenu_border_size+8 more<ul class="pgcatmenu_list">