pagemenu Security & Risk Analysis

wordpress.org/plugins/pagemenu

Pagemenu selects pages from the Wordpress database and presents them in a dropdown menu.

10 active installs v0.1 PHP + WP 2.7.1+ Updated May 6, 2009
cssdatabasedropdownmenus
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is pagemenu Safe to Use in 2026?

Generally Safe

Score 85/100

pagemenu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 17yr ago
Risk Assessment

The "pagemenu" v0.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, file operations, or external HTTP requests is a positive indicator. Crucially, all SQL queries utilize prepared statements, and all outputs are properly escaped, mitigating common injection and XSS risks. The plugin also shows no recorded vulnerabilities (CVEs), which suggests a history of secure development or limited public exposure. However, a significant concern arises from the complete lack of nonces and capability checks. While the attack surface is currently reported as zero, this absence of security controls means that if any entry points were to be introduced in future versions or through other means, they would be entirely unprotected, leaving them vulnerable to unauthorized access or manipulation. The plugin's extremely low version number (0.1) also suggests it is in an early development stage, and its security might not have undergone extensive testing.

Key Concerns

  • No nonce checks for potential future entry points
  • No capability checks for potential future entry points
  • Very early version (0.1) indicates limited testing
Vulnerabilities
None known

pagemenu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

pagemenu Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

pagemenu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries
Attack Surface

pagemenu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_headpagemenu.php:70
actionwp_headpagemenu.php:71
Maintenance & Trust

pagemenu Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedMay 6, 2009
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

pagemenu Developer Profile

rickwright

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect pagemenu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pagemenu/cssmenu.css

HTML / DOM Fingerprints

CSS Classes
cssmenu
FAQ

Frequently Asked Questions about pagemenu