RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Security & Risk Analysis

wordpress.org/plugins/rt-mega-menu

RT Mega Menu is a powerful WordPress mega menu plugin that lets you build advanced, responsive mega menus using Elementor or the Gutenberg block edito …

8K active installs v1.4.3 PHP + WP 6.3+ Updated Apr 5, 2026
elementormega-menumegamenumenuwidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Safe to Use in 2026?

Generally Safe

Score 100/100

RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The rt-mega-menu plugin v1.4.1 demonstrates a generally good security posture based on the provided static analysis. A significant strength is the complete absence of direct SQL injection vulnerabilities, as all detected SQL queries utilize prepared statements. Furthermore, the plugin exhibits a robust approach to protecting its entry points, with all 11 AJAX handlers implementing authentication checks. The absence of known CVEs and a clean vulnerability history also contribute to a positive security assessment, suggesting the developers have a track record of addressing security concerns.

Key Concerns

  • Only 71% of output escaping is proper
  • 5 external HTTP requests
Vulnerabilities
None known

RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Release Timeline

v11.5
v1.4.3Current
v1.4.2
v1.4.1
v1.4.0
v1.3.9
v1.3.8
v1.3.7
v1.3.6
v1.3.5
v1.3.4
v1.3.3
v1.3.2
v1.3.1
v1.3.0
v1.2.9
v1.2.8
v1.2.7
v1.2.6
v1.2.5
Code Analysis
Analyzed Mar 16, 2026

RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
86
207 escaped
Nonce Checks
12
Capability Checks
5
File Operations
0
External Requests
5
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

71% escaped293 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
rtmega_update_menu_options (admin\includes\admin-ajax-request.php:28)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Attack Surface

Entry Points11
Unprotected0

AJAX Handlers 11

authwp_ajax_rtmega_update_menu_optionsadmin\includes\admin-ajax-request.php:8
authwp_ajax_rtmega_get_menu_optionsadmin\includes\admin-ajax-request.php:9
authwp_ajax_rtmega_set_menu_item_mega_buttonadmin\includes\admin-ajax-request.php:10
authwp_ajax_rtmega_delete_menu_optionsadmin\includes\admin-ajax-request.php:11
authwp_ajax_rtmega_get_templates_data_by_sourceadmin\includes\admin-ajax-request.php:13
authwp_ajax_rtmega_create_new_templateadmin\includes\admin-ajax-request.php:14
authwp_ajax_rtmega_get_menu_switchadmin\includes\menu-metabox.php:8
noprivwp_ajax_rtmega_get_menu_switchadmin\includes\menu-metabox.php:9
authwp_ajax_rtmega_ignore_plugin_noticeadmin\includes\notice.php:19
authwp_ajax_import_rtmega_templateadmin\includes\template-library.php:23
noprivwp_ajax_import_rtmega_templateadmin\includes\template-library.php:24
WordPress Hooks 33
actionwp_nav_menu_item_custom_fieldsadmin\includes\admin-ajax-request.php:12
actionadmin_menuadmin\includes\admin-settings.php:10
actionadmin_initadmin\includes\admin-settings.php:11
actionadmin_footeradmin\includes\menu-metabox.php:7
actionadmin_noticesadmin\includes\notice.php:17
actionwp_dashboard_setupadmin\includes\notice.php:18
actionenqueue_block_editor_assetsadmin\includes\plugin-scripts.php:3
actionadmin_enqueue_scriptsadmin\includes\plugin-scripts.php:4
actioninitadmin\includes\post-types.php:7
filterallowed_block_types_alladmin\includes\post-types.php:8
actionadmin_menuadmin\includes\template-library.php:22
actionswitch_themeapps\Insights.php:135
actionswitch_themeapps\Insights.php:136
actionadmin_footerapps\Insights.php:146
actionadmin_noticesapps\Insights.php:161
actionadmin_initapps\Insights.php:164
filtercron_schedulesapps\Insights.php:168
actionadmin_menuapps\License.php:219
actionafter_switch_themeapps\License.php:781
actionswitch_themeapps\License.php:782
actionplugins_loadedclass.rtmega-menu.php:38
actionelementor/widgets/registerclass.rtmega-menu.php:60
actionelementor/elements/categories_registeredclass.rtmega-menu.php:61
actionelementor/elements/categories_registeredclass.rtmega-menu.php:96
filterblock_categories_allpublic\blocks\blocks.php:20
actioninitpublic\blocks\blocks.php:27
actionenqueue_block_assetspublic\includes\plugin-scripts.php:4
actionwp_enqueue_scriptspublic\includes\plugin-scripts.php:5
filterwp_setup_nav_menu_itempublic\includes\rt-mega-menu-terms.php:21
filterwp_nav_menu_argspublic\includes\rt-mega-menu-terms.php:22
actionelementor/element/container/section_layout/after_section_endpublic\includes\rt-mega-menu-terms.php:143
actionwp_headpublic\includes\rtmega-dynamic-css.php:4
actionplugins_loadedrt-mega-menu.php:44
Maintenance & Trust

RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 5, 2026
PHP min version
Downloads58K

Community Trust

Rating100/100
Number of ratings2
Active installs8K
Developer Profile

RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Developer Profile

themewant

8 plugins · 10K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rt-mega-menu/admin/assets/lib/font-awesome/css/all.min.css/wp-content/plugins/rt-mega-menu/admin/assets/css/rtmega-menu-admin.css/wp-content/plugins/rt-mega-menu/admin/assets/js/rtmega-menu-admin.js/wp-content/plugins/rt-mega-menu/admin/assets/js/rtmega-template.js/wp-content/plugins/rt-mega-menu/public/assets/css/rt-mega-menu.css/wp-content/plugins/rt-mega-menu/public/assets/js/rt-mega-menu.js
Script Paths
/wp-content/plugins/rt-mega-menu/admin/assets/js/rtmega-menu-admin.js/wp-content/plugins/rt-mega-menu/admin/assets/js/rtmega-template.js
Version Parameters
rt-mega-menu/admin/assets/lib/font-awesome/css/all.min.css?ver=rt-mega-menu/admin/assets/css/rtmega-menu-admin.css?ver=rt-mega-menu/admin/assets/js/rtmega-menu-admin.js?ver=rt-mega-menu/admin/assets/js/rtmega-template.js?ver=rt-mega-menu/public/assets/css/rt-mega-menu.css?ver=rt-mega-menu/public/assets/js/rt-mega-menu.js?ver=

HTML / DOM Fingerprints

CSS Classes
rt-mega-menu-wraprt-mega-menu-dropdown-containerrt-mega-menu-mobile-headerrt-mega-menu-offcanvas-wraprt-mega-menu-flyout-wrap
HTML Comments
<!-- RT Mega Menu Start --><!-- RT Mega Menu End --><!-- RT Mega Menu Content Start --><!-- RT Mega Menu Content End -->
Data Attributes
data-rtmega-menu-settingsdata-rtmega-templatedata-rtmega-template-id
JS Globals
rtmegamenu_ajaxRTMEGA_MENU_VERSION
FAQ

Frequently Asked Questions about RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg