
QRMenu Restaurant QR Menu Lite Security & Risk Analysis
wordpress.org/plugins/qrmenu-liteQRMenu Lite is an advanced online menu tool for restaurants and other food establishments to manage digital menus right on your websites.
Is QRMenu Restaurant QR Menu Lite Safe to Use in 2026?
Use With Caution
Score 69/100QRMenu Restaurant QR Menu Lite has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The qrmenu-lite plugin version 1.0.4 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. The plugin also implements nonce and capability checks on its entry points, which is a good defense against common web attacks. However, the presence of the `unserialize` function without explicit taint analysis results indicating it's safe is a significant concern, as deserialization vulnerabilities are often critical. Furthermore, a known high-severity vulnerability related to deserialization of untrusted data remains unpatched, indicating a historical pattern of this risk and a critical need for an update. While the static analysis didn't reveal immediate exploit paths for this specific version, the combination of a dangerous function and a historical vulnerability pattern presents a notable risk.
Despite the positive aspects like secure SQL handling and output escaping, the single critical weakness of an unpatched deserialization vulnerability overshadows the plugin's strengths. The existence of the `unserialize` function, even if not directly exploited in the static analysis, makes it a potential vector for future attacks if data is not rigorously validated before being passed to it. The vulnerability history strongly suggests that deserialization is an area where this plugin has struggled. Therefore, users should prioritize updating to a version that has addressed this known high-severity issue to mitigate the risk of data compromise.
Key Concerns
- Unpatched High Severity CVE
- Dangerous function unserialize used
QRMenu Restaurant QR Menu Lite Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
QRMenu Restaurant QR Menu Lite <= 1.0.3 - Authenticated (Contributor+) PHP Object Injection
QRMenu Restaurant QR Menu Lite Release Timeline
QRMenu Restaurant QR Menu Lite Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
QRMenu Restaurant QR Menu Lite Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 33
Maintenance & Trust
QRMenu Restaurant QR Menu Lite Maintenance & Trust
Maintenance Signals
Community Trust
QRMenu Restaurant QR Menu Lite Alternatives
Mima Menu Builder
mima-menu-builder
Build and manage a mobile-friendly digital menu for food, drink, cafe, dessert, and hospitality businesses.
Flavor – Restaurant Menu
flavor-restaurant-menu
A modern, elegant restaurant menu plugin. Card Grid layout, category filter, Elegant Dark theme, all page builders included.
MenuMaster – Interactive Mobile-First Restaurant Menu Plugin for WooCommerce
menumaster-restaurant-menu
Create mobile-friendly restaurant menus that are easy for customers to access by scanning a QR code. Custom tags and filters make navigation simple, h …
Qreatmenu – Restaurant QR Menu for WooCommerce
qreatmenu-restaurant-qr-menu-for-woocommerce
This plugins helps you to create a Restaurant Menu from WooCommerce products. And generate a QR code for your menu.
wMenu Digital Menu and Restaurant Ordering
wmenu-digital-menu-and-restaurant-ordering
wMenu is restaurant Menu and Ordering plugin. wMenu helps site builders to add restaurant Menu, Wine and Drink list into any WordPress theme.
QRMenu Restaurant QR Menu Lite Developer Profile
3 plugins · 70 total installs
How We Detect QRMenu Restaurant QR Menu Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qrmenu-lite/assets/custom-style.css/wp-content/plugins/qrmenu-lite/vendor/bootstrap/css/bootstrap.min.css/wp-content/plugins/qrmenu-lite/vendor/font-awesome/all.min.css/wp-content/plugins/qrmenu-lite/vendor/select2/select2.min.css/wp-content/plugins/qrmenu-lite/vendor/coloris/coloris.min.css/wp-content/plugins/qrmenu-lite/assets/custom-scripts.js/wp-content/plugins/qrmenu-lite/assets/custom-template-style.css/wp-content/plugins/qrmenu-lite/assets/custom-template-scripts.js/wp-content/plugins/qrmenu-lite/vendor/bootstrap/js/bootstrap.bundle.min.js/wp-content/plugins/qrmenu-lite/vendor/gianniAccordion/gianniAccordion.min.js/wp-content/plugins/qrmenu-lite/vendor/gianniAccordion/gianniAccordion.min2.js/wp-content/plugins/qrmenu-lite/vendor/jquery.repeater/jquery.repeater.min.js/wp-content/plugins/qrmenu-lite/vendor/select2/select2.full.min.js/wp-content/plugins/qrmenu-lite/vendor/coloris/coloris.min.jsqrmenu-lite/assets/custom-style.css?ver=qrmenu-lite/vendor/bootstrap/css/bootstrap.min.css?ver=qrmenu-lite/vendor/font-awesome/all.min.css?ver=qrmenu-lite/vendor/select2/select2.min.css?ver=qrmenu-lite/vendor/coloris/coloris.min.css?ver=qrmenu-lite/assets/custom-scripts.js?ver=qrmenu-lite/assets/custom-template-style.css?ver=qrmenu-lite/assets/custom-template-scripts.js?ver=qrmenu-lite/vendor/bootstrap/js/bootstrap.bundle.min.js?ver=qrmenu-lite/vendor/gianniAccordion/gianniAccordion.min.js?ver=qrmenu-lite/vendor/gianniAccordion/gianniAccordion.min2.js?ver=qrmenu-lite/vendor/jquery.repeater/jquery.repeater.min.js?ver=qrmenu-lite/vendor/select2/select2.full.min.js?ver=qrmenu-lite/vendor/coloris/coloris.min.js?ver=HTML / DOM Fingerprints
qrlite-custom-template-styledata-bs-toggledata-bs-targetaria-controlsaria-labelledbydata-bs-parentqrlite_builder_ajax