
RestroPress – Menu Cart Security & Risk Analysis
wordpress.org/plugins/restropress-menu-cartThe RestroPress - Menu Cart plugin is useful for the RestroPress users who want to show a cart menu on the header.
Is RestroPress – Menu Cart Safe to Use in 2026?
Generally Safe
Score 100/100RestroPress – Menu Cart has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "restropress-menu-cart" v1.0.3 plugin exhibits a mixed security posture. On one hand, the absence of any recorded CVEs and the use of prepared statements for SQL queries suggest a degree of attention to common vulnerabilities. However, the static analysis reveals significant concerns regarding its attack surface. With two AJAX handlers identified, and crucially, both lacking authentication checks, this presents a direct pathway for unauthenticated attackers to potentially interact with sensitive functionality.
The code signals are largely positive, with no dangerous functions, no raw SQL, and no file operations, which are good indicators. The presence of external HTTP requests and a moderate rate of output escaping (67%) are areas to monitor, though not immediately critical. Taint analysis results show no identified flows, which is a positive sign that at least in the analyzed paths, sensitive data is being handled securely. The lack of any recorded vulnerabilities in its history is a strength, implying a generally stable codebase.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices in database and file handling, the two unprotected AJAX endpoints are a substantial risk. This creates a clear and easily exploitable attack surface that could lead to unintended actions or data exposure if not addressed. The plugin's strengths lie in its internal code robustness, but its external interface needs immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Lack of nonce checks on AJAX
- Moderate output escaping (67%)
RestroPress – Menu Cart Security Vulnerabilities
RestroPress – Menu Cart Code Analysis
Output Escaping
RestroPress – Menu Cart Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
RestroPress – Menu Cart Maintenance & Trust
Maintenance Signals
Community Trust
RestroPress – Menu Cart Alternatives
RestaurantOps
restaurantops-orders
RestaurantOps enables you to manage your menu, add online ordering, and receive notifications on your Clover System. RestaurantOps is the best way to …
RestroPress – Address Auto Complete
restropress-address-auto-complete
"RestroPress - Address Auto Complete" enhances the ordering process by suggesting addresses as users type, improving accuracy and efficiency.
Smart Menupad
smart-menupad
Plugin to keep your menu at one place and sync to your own wordpress website from smart menupad platform.
Smart Online Order for Clover
clover-online-orders
Smart Online Order for Clover allows you to receive orders from your Wordpress website and have it sent directly to your Clover POS.
Menu Cart Divi
menu-cart-divi
Enhance your Divi Builder with the 'Menu Cart Module Divi' plugin. It adds a new module to display a cart icon with item count and price, im …
RestroPress – Menu Cart Developer Profile
8 plugins · 2K total installs
How We Detect RestroPress – Menu Cart
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/restropress-menu-cart/admin/css/restropress-menu-cart-admin.css/wp-content/plugins/restropress-menu-cart/admin/js/restropress-menu-cart-admin.js/wp-content/plugins/restropress-menu-cart/public/css/restropress-menu-cart-public.css/wp-content/plugins/restropress-menu-cart/public/js/restropress-menu-cart-public.jsadmin/js/restropress-menu-cart-admin.jspublic/js/restropress-menu-cart-public.jsrestropress-menu-cart-admin.css?ver=restropress-menu-cart-admin.js?ver=restropress-menu-cart-public.css?ver=restropress-menu-cart-public.js?ver=HTML / DOM Fingerprints
menu_cart_headingdisplay_icondisplay_menudata-cart-idrestropress_menu_cart_params[restropress_menu_cart]