
Post Hierarchy Menu Security & Risk Analysis
wordpress.org/plugins/post-hierarchy-menuAdds a widget that will display a nested list of any post type based on it's hierarchy.
Is Post Hierarchy Menu Safe to Use in 2026?
Generally Safe
Score 85/100Post Hierarchy Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "post-hierarchy-menu" plugin, in version 0.0.1, exhibits a concerning security posture primarily due to the lack of proper authentication and authorization checks on its AJAX endpoints. While the code boasts no known vulnerabilities historically and utilizes prepared statements for SQL queries, the absence of security controls on two AJAX handlers exposes a significant attack surface. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure if vulnerabilities exist within their functionality. The limited static analysis also reveals a low percentage of properly escaped output, increasing the risk of cross-site scripting (XSS) attacks. Despite the lack of critical taint flows and dangerous functions, the critical oversight in securing AJAX handlers and the insufficient output escaping practices present immediate risks.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
Post Hierarchy Menu Security Vulnerabilities
Post Hierarchy Menu Code Analysis
Output Escaping
Post Hierarchy Menu Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
Post Hierarchy Menu Maintenance & Trust
Maintenance Signals
Community Trust
Post Hierarchy Menu Alternatives
Admin Menu Tree Page View
admin-menu-tree-page-view
Get a tree view of all your pages directly in the admin menu. Search, add, edit, view, re-order – all is just one click away!
Advanced Sidebar Menu
advanced-sidebar-menu
Fully automatic sidebar menus.
Current Menu Item for Custom Post Types
current-menu-item-for-custom-post-types
Allows you to highlight the current menu item by assigning a page to a custom post type.
Hierarchy
hierarchy
Move your Pages/Posts/Custom Post Type admin links from the sidebar to a Content menu that nests everything where it should be
Comments by Post Type
comments-by-post-type
Separate comments by post type in admin menu.
Post Hierarchy Menu Developer Profile
2 plugins · 20 total installs
How We Detect Post Hierarchy Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-hierarchy-menu/HTML / DOM Fingerprints
post-hierarchy-menudata-posttype