SideMenu Security & Risk Analysis

wordpress.org/plugins/sidemenu

Injects a sliding side menu / sidebar into any theme!

1K active installs v1.8.9 PHP 5.6+ WP 4.6+ Updated Dec 17, 2025
side-menuside-navslide-menuvertical-menu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SideMenu Safe to Use in 2026?

Generally Safe

Score 100/100

SideMenu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The sidemenu plugin v1.8.9 exhibits a generally good security posture, with several positive indicators. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The high percentage of properly escaped outputs and the presence of nonce and capability checks further suggest a conscious effort towards secure coding practices. The plugin also has no recorded vulnerability history, indicating a stable and likely well-maintained codebase.

However, a significant concern arises from the identified attack surface. The plugin exposes one AJAX handler that lacks authentication checks. This creates a direct entry point for unauthenticated users to interact with the plugin's functionality, which could potentially be exploited if not properly secured within the handler itself. While the static analysis didn't reveal any critical or high severity taint flows, the lack of authorization on an AJAX endpoint is a fundamental security weakness that could lead to unauthorized actions or information disclosure depending on the handler's implementation.

In conclusion, while the plugin demonstrates strengths in many areas of secure development, the unprotected AJAX handler presents a notable risk. Addressing this specific entry point with appropriate authentication and authorization checks should be a priority to enhance the plugin's overall security. The strong track record of no past vulnerabilities is a positive sign, but proactive mitigation of the identified exposure is crucial.

Key Concerns

  • AJAX handler without auth checks
Vulnerabilities
None known

SideMenu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SideMenu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
143 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped148 total outputs
Attack Surface
1 unprotected

SideMenu Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_dismiss_sidemenu_notice_handlersidemenu.php:75

Shortcodes 1

[sidemenu] sidemenu.php:87
WordPress Hooks 18
filterplugin_row_metaincludes\class-sidemenu-common.php:287
actionwidgets_initsidemenu.php:65
actioncustomize_registersidemenu.php:66
actionafter_setup_themesidemenu.php:67
filternav_menu_meta_box_objectsidemenu.php:68
filterhidden_meta_boxessidemenu.php:69
actionadmin_noticessidemenu.php:74
filterwidget_form_callbacksidemenu.php:76
actionadmin_headsidemenu.php:77
actioncustomize_controls_print_stylessidemenu.php:78
actioncustomize_controls_enqueue_scriptssidemenu.php:79
actioncustomize_preview_initsidemenu.php:83
actionwp_enqueue_scriptssidemenu.php:84
actionwp_footersidemenu.php:85
actionwp_headsidemenu.php:86
filterdynamic_sidebar_paramssidemenu.php:88
actioninitsidemenu.php:92
filterwalker_nav_menu_start_elsidemenu.php:919
Maintenance & Trust

SideMenu Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 17, 2025
PHP min version5.6
Downloads70K

Community Trust

Rating96/100
Number of ratings24
Active installs1K
Developer Profile

SideMenu Developer Profile

Oliver Campion

12 plugins · 43K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
869 days
View full developer profile
Detection Fingerprints

How We Detect SideMenu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sidemenu/css/sidemenu-free.css/wp-content/plugins/sidemenu/js/sidemenu-free.js
Script Paths
/wp-content/plugins/sidemenu/js/sidemenu-free.js
Version Parameters
sidemenu/css/sidemenu-free.css?ver=sidemenu/js/sidemenu-free.js?ver=

HTML / DOM Fingerprints

CSS Classes
sidemenu-wrappersidemenu-opensidemenu-sidebarsidemenu-closesidemenu-button-wrappersidemenu-toggle-icon
HTML Comments
<!-- SideMenu Close Button --><!-- SideMenu Open Button --><!-- SideMenu Wrapper -->
Data Attributes
data-sidemenu-id
JS Globals
sidemenuConfigsidemenu
Shortcode Output
[sidemenu]
FAQ

Frequently Asked Questions about SideMenu