
Quick Restaurant Menu Security & Risk Analysis
wordpress.org/plugins/quick-restaurant-menuCreate easily restaurant menus with drag and drop.
Is Quick Restaurant Menu Safe to Use in 2026?
Mostly Safe
Score 82/100Quick Restaurant Menu is generally safe to use though it hasn't been updated recently. 5 past CVEs were resolved. Keep it updated.
The quick-restaurant-menu plugin v2.1.0 exhibits a mixed security posture. On the positive side, the code analysis shows a strong adherence to secure coding practices with 100% of SQL queries using prepared statements and a very high rate of output escaping (87%). The absence of dangerous functions, file operations, and external HTTP requests is also commendable. The plugin also implements a reasonable number of nonce and capability checks across its entry points. However, a significant concern arises from the presence of one unprotected AJAX handler, representing a direct entry point without proper authentication, which could lead to unauthorized actions.
The plugin's vulnerability history paints a concerning picture, with a total of 5 known CVEs, including 3 high and 2 medium severity vulnerabilities. The common types of these past vulnerabilities (Missing Authorization, CSRF, Authorization Bypass, XSS) suggest recurring patterns of authorization and input validation issues. Although there are currently no unpatched CVEs, the historical prevalence of these serious vulnerability types indicates a potential for similar issues to resurface if not rigorously addressed. In conclusion, while the plugin demonstrates good secure coding fundamentals in its current version, the past vulnerability record and the identified unprotected AJAX handler necessitate careful monitoring and a proactive approach to security.
Key Concerns
- Unprotected AJAX handler
- 5 total known CVEs (3 high, 2 medium)
- Recurring vulnerability types (Auth, CSRF, XSS)
- Low percentage of fully escaped outputs (87%)
Quick Restaurant Menu Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Quick Restaurant Menu <= 2.0.2 - Missing Authorization
Quick Restaurant Menu <= 2.0.2 - Cross-Site Request Forgery
Quick Restaurant Menu <= 2.0.2 - Authenticated (Administrator+) Cross-Site Scripting
Quick Restaurant Menu <= 2.0.2 - Insecure Direct Object Reference
Quick Restaurant Menu <= 2.0.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Quick Restaurant Menu Code Analysis
Output Escaping
Quick Restaurant Menu Attack Surface
AJAX Handlers 5
Shortcodes 2
WordPress Hooks 30
Maintenance & Trust
Quick Restaurant Menu Maintenance & Trust
Maintenance Signals
Community Trust
Quick Restaurant Menu Alternatives
Phoca Restaurant Menu Block
phoca-restaurant-menu-block
Create menus for various establishments, such as restaurants, cafeterias, fast-food joints, school canteens, buffets, bars, clubs, ...
Phoca Restaurant Menu Groups Items Block
phoca-restaurant-menu-groups-and-items-block
Phoca Restaurant Menu Groups and Items Block is a Gutenberg plugin that works together with its parent block Phoca Restaurant Block
Restaurant Menu – Food Ordering System – Table Reservation
menu-ordering-reservations
Create a restaurant menu and start taking food orders online, with no commissions or costs. Table reservations are also available for free.
Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin
orderable
Take your restaurant/food business online with the online ordering system plugin for WordPress, Orderable.
Food Menu – Restaurant Menu & Online Ordering for WooCommerce
tlp-food-menu
A Simple Food & Restaurant Menu Display Plugin for Restaurant, Cafes, Fast Food, Coffee House with WooCommerce Online Ordering.
Quick Restaurant Menu Developer Profile
2 plugins · 3K total installs
How We Detect Quick Restaurant Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/quick-restaurant-menu/assets/js/erm_menu/main.js/wp-content/plugins/quick-restaurant-menu/assets/js/jquery.magnific-popup.min.js/wp-content/plugins/quick-restaurant-menu/assets/js/erm-front-scripts.js/wp-content/plugins/quick-restaurant-menu/assets/css/magnific-popup.css/wp-content/plugins/quick-restaurant-menu/assets/css/erm-front.css/wp-content/plugins/quick-restaurant-menu/assets/js/erm_menu/main.js/wp-content/plugins/quick-restaurant-menu/assets/js/jquery.magnific-popup.min.js/wp-content/plugins/quick-restaurant-menu/assets/js/erm-front-scripts.jsquick-restaurant-menu/assets/css/erm-front.css?ver=quick-restaurant-menu/assets/js/erm_menu/main.js?ver=quick-restaurant-menu/assets/js/erm-front-scripts.js?ver=HTML / DOM Fingerprints
erm-menu-itemdata-erm-idERM_MENU[erm_menu][erm_menu_week]