QuadMenu – OceanWP Mega Menu Security & Risk Analysis

wordpress.org/plugins/quadmenu-oceanwp

Integrates QuadMenu with the OceanWP theme. Requires QuadMenu and OceanWP.

300 active installs v1.0.4 PHP + WP 4.8+ Updated Mar 15, 2021
divimega-menumegamenumenuquadmenu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is QuadMenu – OceanWP Mega Menu Safe to Use in 2026?

Generally Safe

Score 85/100

QuadMenu – OceanWP Mega Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "quadmenu-oceanwp" v1.0.4 plugin exhibits a generally positive security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, and there are no file operations or external HTTP requests. The absence of known vulnerabilities in its history is also a strong indicator of good security practices. However, a significant concern arises from the output escaping analysis, where 100% of the detected outputs are not properly escaped. This means that sensitive data rendered by the plugin could be vulnerable to Cross-Site Scripting (XSS) attacks if the data originates from untrusted sources. While the attack surface appears minimal and protected, the lack of output escaping presents a tangible risk that needs to be addressed.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

QuadMenu – OceanWP Mega Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

QuadMenu – OceanWP Mega Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

QuadMenu – OceanWP Mega Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_noticesquadmenu-oceanwp.php:22
filterquadmenu_developer_optionsquadmenu-oceanwp.php:23
filterquadmenu_default_themesquadmenu-oceanwp.php:24
filterquadmenu_default_optionsquadmenu-oceanwp.php:25
filterquadmenu_default_options_socialquadmenu-oceanwp.php:26
filterquadmenu_default_options_theme_oceanwpquadmenu-oceanwp.php:27
filterquadmenu_default_options_location_main_menuquadmenu-oceanwp.php:28
actionocean_headerquadmenu-oceanwp.php:334
Maintenance & Trust

QuadMenu – OceanWP Mega Menu Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.0
Last updatedMar 15, 2021
PHP min version
Downloads25K

Community Trust

Rating100/100
Number of ratings1
Active installs300
Developer Profile

QuadMenu – OceanWP Mega Menu Developer Profile

QuadMenu

7 plugins · 2K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect QuadMenu – OceanWP Mega Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quadmenu-oceanwp/quadmenu-oceanwp.php

HTML / DOM Fingerprints

CSS Classes
quadmenu-oceanwp
Data Attributes
data-theme='oceanwp'
FAQ

Frequently Asked Questions about QuadMenu – OceanWP Mega Menu