Purify Menus Security & Risk Analysis

wordpress.org/plugins/purify-wp-menues

Improve page speed by letting slim down the HTML code of menus and category lists to the only CSS classes and attributes your theme needs.

300 active installs v3.5.0 PHP 5.2+ WP 4.6+ Updated Apr 15, 2026
cssmenusnavigation-menupage-speedperformance
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Purify Menus Safe to Use in 2026?

Generally Safe

Score 100/100

Purify Menus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "purify-wp-menues" v3.5.0 demonstrates a strong security posture based on the provided static analysis. It exhibits no known vulnerabilities, no critical taint flows, and avoids dangerous functions. The code correctly utilizes prepared statements for all SQL queries and appears to handle output escaping effectively, with only a small percentage of outputs potentially unescaped. The minimal attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces the plugin's exposure to external threats. The presence of a capability check further adds a layer of access control.

Key Concerns

  • Small percentage of outputs not properly escaped
  • No nonce checks found
Vulnerabilities
None known

Purify Menus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Purify Menus Release Timeline

v3.5.0Current
v3.4.1
v3.4
v3.3.3
v3.3.2
v3.3.1
v3.3.0
v3.2.2
v3.2.1
v3.2
v3.1.1
v3.1
v3.0.5
v3.0.4
v3.0.3
v3.0.2
v3.0.1
v3.0
Code Analysis
Analyzed Mar 16, 2026

Purify Menus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
13 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped14 total outputs
Attack Surface

Purify Menus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_enqueue_scriptsincludes\class-PWM_Default.php:179
actionadmin_menuincludes\class-PWM_Default.php:183
actionadmin_initincludes\class-PWM_Default.php:190
actionadmin_noticesincludes\class-PWM_Default.php:197
actionnav_menu_css_classincludes\class-PWM_Default.php:215
actionpage_css_classincludes\class-PWM_Default.php:218
actionnav_menu_item_idincludes\class-PWM_Default.php:223
actioncategory_css_classincludes\class-PWM_Default.php:227
Maintenance & Trust

Purify Menus Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedApr 15, 2026
PHP min version5.2
Downloads32K

Community Trust

Rating100/100
Number of ratings6
Active installs300
Developer Profile

Purify Menus Developer Profile

Kybernetik Services

10 plugins · 167K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Purify Menus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/purify-wp-menues/admin/css/hinjipwpm-admin.css/wp-content/plugins/purify-wp-menues/js/hinjipwpm-admin.js
Script Paths
js/hinjipwpm-admin.js
Version Parameters
hinjipwpm-admin.css?ver=hinjipwpm-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
pwpm-menu-item-classespwpm-menu-link-classespwpm-menu-idpwpm-menu-link-id
Data Attributes
data-pwpm-menu-iddata-pwpm-menu-link-id
JS Globals
PWM_Admin
FAQ

Frequently Asked Questions about Purify Menus