
Show Menu Shortcode Security & Risk Analysis
wordpress.org/plugins/show-menu-shortcodeProvides a [show-menu] shortcode for displaying a menu within a post or page.
Is Show Menu Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100Show Menu Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "show-menu-shortcode" plugin v1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the exclusive use of prepared statements for SQL queries are excellent practices. Furthermore, all output is properly escaped, and the plugin does not appear to bundle any external libraries that could introduce vulnerabilities. The attack surface is minimal, consisting of a single shortcode, and importantly, there are no unauthenticated entry points detected.
The lack of any identified taint flows, even with zero flows analyzed, combined with a clean vulnerability history with no recorded CVEs, further strengthens the assessment of its current security. This suggests the developers have been diligent in writing secure code and maintaining it. However, a key area of concern is the complete absence of nonce checks and capability checks. While the current entry points are limited and seemingly protected, this leaves the shortcode vulnerable to potential CSRF attacks or unauthorized execution if a future version or an interaction with another plugin were to expose it in a way that bypasses initial protections.
In conclusion, "show-menu-shortcode" v1.0 demonstrates good coding practices regarding data handling and SQL security. Its clean vulnerability history is a significant positive. The primary weakness lies in the lack of robust authentication and authorization mechanisms (nonces and capability checks) on its sole entry point, which represents a potential, albeit currently theoretical, risk. While the current state is very good, neglecting these checks could become an issue in more complex scenarios.
Key Concerns
- Missing nonce checks
- Missing capability checks
Show Menu Shortcode Security Vulnerabilities
Show Menu Shortcode Code Analysis
Show Menu Shortcode Attack Surface
Shortcodes 1
Maintenance & Trust
Show Menu Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Show Menu Shortcode Alternatives
Show All Posts Shortcode
show-aposts-shortcode
Provides a [show-aposts] shortcode for displaying posts or pages within a post or page using the get_posts() function.
Popular Brand Icons – Simple Icons
simple-icons
An easy to use lightweight SVG icons plugin with over 1500+ brand icons. Use these icons in your menus, widgets, posts, or pages.
BuddyMenu BuddyLinks
buddymenu-buddylinks
BuddyPress BuddyLinks does three things really well:
Easy menus
jquery-easy-menu
Plugin to load different types of menus with pictures.
DCO Shortcodes Menu
dco-shortcodes-menu
Allow you to add shortcodes menu to the editor
Show Menu Shortcode Developer Profile
2 plugins · 420 total installs
How We Detect Show Menu Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
menu-container<div class="menu-container"><ul class="menu">