Responsive Menu Card | Price List Items Security & Risk Analysis

wordpress.org/plugins/responsive-menu-card-price-list-items

Create a customized and responsive menu card with price list items to your site.

200 active installs v1.6 PHP + WP 3.0+ Updated Apr 27, 2017
category-items-filtermenu-cardprice-list-itemsprice-tableresponsive-menu-card
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Responsive Menu Card | Price List Items Safe to Use in 2026?

Generally Safe

Score 85/100

Responsive Menu Card | Price List Items has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin "responsive-menu-card-price-list-items" v1.6 demonstrates a generally good security posture in several areas, notably the absence of known vulnerabilities and the use of prepared statements for all SQL queries. The static analysis reveals no critical or high severity taint flows, and the plugin does not perform external HTTP requests. However, there are significant concerns regarding output escaping and the handling of file operations. A very low percentage of output is properly escaped, indicating a high risk of cross-site scripting (XSS) vulnerabilities, especially given the presence of a shortcode which serves as an entry point. The presence of file operations without further context raises questions about their security implications, though no specific vulnerabilities are immediately evident. The lack of nonce checks is a notable weakness, particularly for any functionality that might be triggered via AJAX, although no AJAX handlers were found. Overall, while the plugin avoids common pitfalls like unpatched CVEs and raw SQL, the poor output escaping practices present a substantial risk that needs immediate attention.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks found
  • File operations present without clear sanitization context
Vulnerabilities
None known

Responsive Menu Card | Price List Items Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Responsive Menu Card | Price List Items Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

7% escaped29 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
rmc_handle_file_upload (includes\responsive-call.php:84)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Responsive Menu Card | Price List Items Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[menu-card] responsive-menu-card.php:62
WordPress Hooks 19
actionmenu_cat_add_form_fieldsincludes\responsive-call.php:19
actionmenu_cat_edit_form_fieldsincludes\responsive-call.php:20
actioninitincludes\responsive-call.php:23
actioninitincludes\taxonomy-meta.php:18
filtermanage_edit-menu_cat_columnsincludes\taxonomy-meta.php:23
filtermanage_menu_cat_custom_columnincludes\taxonomy-meta.php:25
actionedited_menu_catincludes\taxonomy-meta.php:27
actioncreate_menu_catincludes\taxonomy-meta.php:28
actionedit_menu_catincludes\taxonomy-meta.php:29
actioncreate_menu_catincludes\taxonomy-meta.php:30
actionedit_tag_form_fieldsincludes\taxonomy-meta.php:31
actionedited_termsincludes\taxonomy-meta.php:32
actioninitresponsive-menu-card.php:59
actioninitresponsive-menu-card.php:60
actionwp_enqueue_scriptsresponsive-menu-card.php:63
actionadmin_enqueue_scriptsresponsive-menu-card.php:64
actionadd_meta_boxesresponsive-menu-card.php:65
actionsave_postresponsive-menu-card.php:67
actionadmin_menuresponsive-menu-card.php:68
Maintenance & Trust

Responsive Menu Card | Price List Items Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedApr 27, 2017
PHP min version
Downloads11K

Community Trust

Rating84/100
Number of ratings5
Active installs200
Developer Profile

Responsive Menu Card | Price List Items Developer Profile

mgulzar

2 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Responsive Menu Card | Price List Items

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/responsive-menu-card-price-list-items/assets/js/jquery.custom.js/wp-content/plugins/responsive-menu-card-price-list-items/assets/css/admin.css/wp-content/plugins/responsive-menu-card-price-list-items/assets/js/jquery.main.js/wp-content/plugins/responsive-menu-card-price-list-items/assets/js/jquery.rmc.js/wp-content/plugins/responsive-menu-card-price-list-items/assets/css/rmc.css/wp-content/plugins/responsive-menu-card-price-list-items/assets/css/theme.php
Script Paths
/wp-content/plugins/responsive-menu-card-price-list-items/assets/js/jquery.custom.js/wp-content/plugins/responsive-menu-card-price-list-items/assets/js/jquery.main.js/wp-content/plugins/responsive-menu-card-price-list-items/assets/js/jquery.rmc.js
Version Parameters
responsive-menu-card-price-list-items/assets/js/jquery.custom.js?ver=responsive-menu-card-price-list-items/assets/css/admin.css?ver=responsive-menu-card-price-list-items/assets/js/jquery.main.js?ver=responsive-menu-card-price-list-items/assets/js/jquery.rmc.js?ver=responsive-menu-card-price-list-items/assets/css/rmc.css?ver=responsive-menu-card-price-list-items/assets/css/theme.php?ver=

HTML / DOM Fingerprints

CSS Classes
rmc-menu-card-containerrmc-menu-item-wraprmc-menu-item-image-wraprmc-menu-item-contentrmc-menu-item-titlermc-menu-item-pricermc-menu-item-descriptionrmc-menu-category-title+3 more
Data Attributes
rmc_menu_cat_ordermenu-order-selectmenu-order-select-byrmc_menu_display_order
JS Globals
rmc_menu_meta_settings
Shortcode Output
[menu-card]
FAQ

Frequently Asked Questions about Responsive Menu Card | Price List Items