Simple Menu Security & Risk Analysis

wordpress.org/plugins/simple-menu

Hide all non-essential and confusing Items from Admin Menu.

0 active installs v1.0 PHP + WP 4.0.1+ Updated Jan 28, 2018
backendhide-itemsmenu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Menu Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of the 'simple-menu' v1.0 plugin reveals a strong security posture. There are no identified attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, none of these potential entry points are unprotected. The code also demonstrates excellent security practices, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. File operations and external HTTP requests are also absent, and crucially, there are no nonce or capability checks, which might indicate reliance on WordPress core's internal handling or a lack of features that would necessitate these checks. The absence of any taint analysis findings further reinforces the clean code base.

The vulnerability history for this plugin is also exceptionally clean, with zero recorded CVEs of any severity. This indicates a consistent history of secure development or a lack of discovered vulnerabilities over time. The plugin appears to have been developed with security as a priority, utilizing best practices for input handling and output sanitization, and presenting a minimal attack surface. There are no immediate red flags or specific risks identified in this analysis, making it a relatively safe plugin based on the provided data.

Vulnerabilities
None known

Simple Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Simple Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Simple Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menusimple-menu.php:17
actionwp_dashboard_setupsimple-menu.php:52
Maintenance & Trust

Simple Menu Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 28, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Simple Menu Developer Profile

Eric-Oliver Mächler

11 plugins · 5K total installs

96
trust score
Avg Security Score
94/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Simple Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
rss-widget
FAQ

Frequently Asked Questions about Simple Menu