QuadMenu – GeneratePress Mega Menu Security & Risk Analysis

wordpress.org/plugins/quadmenu-generatepress

Create a Mega Menu in GeneratePress.

100 active installs v1.0.4 PHP + WP 4.8+ Updated Mar 15, 2021
generatepressgeneratepress-megamenugeneratepress-menuquadmenu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is QuadMenu – GeneratePress Mega Menu Safe to Use in 2026?

Generally Safe

Score 85/100

QuadMenu – GeneratePress Mega Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "quadmenu-generatepress" plugin v1.0.4 demonstrates a strong security posture based on the provided static analysis. The plugin exhibits good security practices, notably the absence of dangerous functions, SQL queries executed without prepared statements, and no file operations or external HTTP requests. All entry points, including AJAX handlers, are protected by capability checks and a nonce check is present, indicating a proactive approach to preventing unauthorized access and potential cross-site request forgery (CSRF) attacks. The lack of any recorded vulnerabilities, critical or otherwise, further strengthens this positive assessment.

While the static analysis reveals no immediate critical risks such as unsanitized taint flows or raw SQL queries, a minor concern arises from the output escaping. With 67% of outputs properly escaped, there's still a possibility of 33% of outputs being unescaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered. However, the absence of critical taint flows and the presence of capability checks on the two AJAX handlers mitigate this risk significantly, suggesting that the unescaped outputs may not be directly exploitable in a severe manner.

In conclusion, "quadmenu-generatepress" v1.0.4 appears to be a secure plugin. Its strengths lie in its robust handling of SQL, file operations, and external requests, along with good authentication and authorization mechanisms for its entry points. The only area requiring a slight caution is the incomplete output escaping, which, while not currently a critical flaw given other protections, should ideally be addressed to achieve a perfect security score.

Key Concerns

  • Outputs not properly escaped
Vulnerabilities
None known

QuadMenu – GeneratePress Mega Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

QuadMenu – GeneratePress Mega Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
4 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped6 total outputs
Attack Surface

QuadMenu – GeneratePress Mega Menu Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_quadmenu_generatepress_customizedquadmenu-generatepress.php:51
noprivwp_ajax_quadmenu_generatepress_customizedquadmenu-generatepress.php:53
WordPress Hooks 8
actionadmin_noticesquadmenu-generatepress.php:45
filterwp_nav_menu_itemsquadmenu-generatepress.php:49
filterwp_headquadmenu-generatepress.php:55
actioncustomize_preview_initquadmenu-generatepress.php:57
filterquadmenu_default_themesquadmenu-generatepress.php:59
filterquadmenu_developer_optionsquadmenu-generatepress.php:61
filterquadmenu_default_optionsquadmenu-generatepress.php:63
filterquadmenu_global_js_dataquadmenu-generatepress.php:188
Maintenance & Trust

QuadMenu – GeneratePress Mega Menu Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.0
Last updatedMar 15, 2021
PHP min version
Downloads8K

Community Trust

Rating40/100
Number of ratings6
Active installs100
Developer Profile

QuadMenu – GeneratePress Mega Menu Developer Profile

QuadMenu

7 plugins · 2K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect QuadMenu – GeneratePress Mega Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/quadmenu-generatepress/assets/quadmenu-generatepress.js
Version Parameters
quadmenu-generatepress/assets/quadmenu-generatepress.js?ver=

HTML / DOM Fingerprints

CSS Classes
quadmenu-itemquadmenu-item-level-0quadmenu-float-opposite
Data Attributes
data-quadmenu-generatepress
JS Globals
quadmenu
FAQ

Frequently Asked Questions about QuadMenu – GeneratePress Mega Menu