
Postmenu Security & Risk Analysis
wordpress.org/plugins/postmenuDuplicate (Clone) Posts, Pages, Menus, Menu links (Items of Menu) and Taxonomies. Easily add any Post or Page to the Menus, Display options in the men …
Is Postmenu Safe to Use in 2026?
Generally Safe
Score 85/100Postmenu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "postmenu" plugin v1.4.2 presents a mixed security posture. While it demonstrates good practices in terms of SQL query handling and a lack of known vulnerabilities, significant concerns arise from its attack surface and output sanitization. The presence of 11 AJAX handlers without authentication checks is a critical weakness, creating numerous potential entry points for unauthorized actions.
Furthermore, the taint analysis reveals 9 flows with unsanitized paths, indicating a risk of insecure data handling. The code also exhibits a substantial number of outputs (44%) that are not properly escaped, leading to a high potential for Cross-Site Scripting (XSS) vulnerabilities. Although there is no known vulnerability history, this does not negate the immediate risks identified in the static and taint analysis. The plugin's strengths lie in its secure SQL practices and the absence of documented CVEs, but these are overshadowed by the exposure of its AJAX endpoints and insufficient output sanitization.
Key Concerns
- AJAX handlers without authentication checks
- Flows with unsanitized paths
- Improperly escaped output
- Large attack surface without auth
Postmenu Security Vulnerabilities
Postmenu Code Analysis
Output Escaping
Data Flow Analysis
Postmenu Attack Surface
AJAX Handlers 11
Shortcodes 1
WordPress Hooks 24
Maintenance & Trust
Postmenu Maintenance & Trust
Maintenance Signals
Community Trust
Postmenu Alternatives
CodingBunny Easy Duplicate Post
coding-bunny-easy-duplicate-post
Clone WordPress page, post and custom post types.
Yoast Duplicate Post
duplicate-post
The go-to tool for cloning posts and pages, including the powerful Rewrite & Republish feature.
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Duplicate Post
copy-delete-posts
Duplicate post
Duplicate Page and Post
duplicate-wp-page-post
Duplicate post, Duplicate page and Duplicate custom post or clone page and clone post.
Postmenu Developer Profile
1 plugin · 40 total installs
How We Detect Postmenu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/postmenu/css/postmenu-admin.css/wp-content/plugins/postmenu/js/postmenu-admin.jsjs/postmenu-admin.jspostmenu-admin.css?ver=postmenu-admin.js?ver=HTML / DOM Fingerprints
data-wp-postmenupostmenu_success_message