QuadMenu – Avada Mega Menu Security & Risk Analysis

wordpress.org/plugins/quadmenu-avada

Integrates QuadMenu Mega Menu with the Avada theme. Requires QuadMenu and Avada.

200 active installs v1.1.7 PHP + WP 4.8+ Updated Mar 15, 2021
avadaavada-megamenuavada-menuquadmenu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is QuadMenu – Avada Mega Menu Safe to Use in 2026?

Generally Safe

Score 85/100

QuadMenu – Avada Mega Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "quadmenu-avada" plugin v1.1.7 exhibits a seemingly strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries use prepared statements, and there are no external HTTP requests or file operations. The absence of known vulnerabilities in its history further suggests a relatively secure implementation. However, a significant concern arises from the output escaping. With 100% of its identified outputs unescaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. While the plugin has no known CVEs, the lack of proper output escaping is a critical weakness that needs immediate attention. The lack of any identified entry points in the static analysis is unusual and may indicate either a very limited plugin functionality or a limitation in the static analysis tool's ability to identify them. Despite the positive signs, the unescaped output represents a tangible and serious security flaw.

Key Concerns

  • All identified outputs are unescaped.
Vulnerabilities
None known

QuadMenu – Avada Mega Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

QuadMenu – Avada Mega Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

QuadMenu – Avada Mega Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_noticesquadmenu-avada.php:22
filterquadmenu_developer_optionsquadmenu-avada.php:23
filterquadmenu_default_themesquadmenu-avada.php:24
filterquadmenu_default_optionsquadmenu-avada.php:25
filterquadmenu_default_options_socialquadmenu-avada.php:26
filterquadmenu_default_options_theme_avadaquadmenu-avada.php:27
filterquadmenu_default_options_location_main_navigationquadmenu-avada.php:28
actionwp_enqueue_scriptsquadmenu-avada.php:30
actionadmin_enqueue_scriptsquadmenu-avada.php:31
Maintenance & Trust

QuadMenu – Avada Mega Menu Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.0
Last updatedMar 15, 2021
PHP min version
Downloads15K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

QuadMenu – Avada Mega Menu Developer Profile

QuadMenu

7 plugins · 2K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect QuadMenu – Avada Mega Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quadmenu-avada/css/quadmenu-avada.css/wp-content/plugins/quadmenu-avada/js/quadmenu-avada.js
Script Paths
/wp-content/plugins/quadmenu-avada/js/quadmenu-avada.js
Version Parameters
quadmenu-avada/css/quadmenu-avada.css?ver=quadmenu-avada/js/quadmenu-avada.js?ver=

HTML / DOM Fingerprints

CSS Classes
quadmenu-avadaquadmenu-navbar-nav
HTML Comments
<!-- Plugin Name: QuadMenu - Avada Mega Menu --><!-- Plugin URI: https://quadmenu.com --><!-- Description: Integrates QuadMenu with the Avada theme. --><!-- Version: 1.1.7 -->+4 more
Data Attributes
data-parentdata-toggle
JS Globals
QuadMenu_Avada
FAQ

Frequently Asked Questions about QuadMenu – Avada Mega Menu