SlickNav Mobile Menu Security & Risk Analysis

wordpress.org/plugins/slicknav-mobile-menu

This plugin adds the option to use the SlickNav Responsive Mobile Menu in place of a regular menu at a designated size.

3K active installs v1.9.3 PHP + WP 4.0+ Updated Jun 29, 2025
accessibleariamenumobileresponsive
100
A · Safe
CVEs total1
Unpatched0
Last CVEDec 9, 2023
Safety Verdict

Is SlickNav Mobile Menu Safe to Use in 2026?

Generally Safe

Score 100/100

SlickNav Mobile Menu has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 9, 2023Updated 9mo ago
Risk Assessment

The slicknav-mobile-menu plugin v1.9.3 demonstrates a generally strong security posture based on the static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events, combined with a complete lack of unsanitized taint flows, significantly reduces the immediate attack surface. The code also shows good practices in SQL query handling, with 100% using prepared statements, and a high percentage of output escaping, indicating an effort to prevent common web vulnerabilities. The presence of capability checks also adds a layer of defense. However, the plugin is not entirely without risk. The vulnerability history reveals one known CVE, which, while currently patched, points to a past weakness. The common vulnerability type associated with this CVE was Cross-site Scripting, a significant concern. The lack of explicit nonce checks on entry points, if any were to emerge, could be a potential area for exploitation, although the current analysis indicates zero unprotected entry points.

Key Concerns

  • Known CVE exists, although patched
  • Zero nonce checks detected
  • Some output not properly escaped
Vulnerabilities
1

SlickNav Mobile Menu Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-51548medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SlickNav Mobile Menu <= 1.9.2 - Authenticated (Admin+) Stored Cross-Site Scripting

Dec 9, 2023 Patched in 1.9.3 (45d)
Code Analysis
Analyzed Mar 16, 2026

SlickNav Mobile Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
35 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped41 total outputs
Attack Surface

SlickNav Mobile Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwp_enqueue_scriptsinc\inlinecss.php:250
actionplugins_loadedslicknav-mobile-menu.php:29
actionwp_enqueue_scriptsslicknav-mobile-menu.php:114
actionadmin_menuslicknav-mobile-menu.php:134
actionadmin_initslicknav-mobile-menu.php:443
actionadmin_enqueue_scriptsslicknav-mobile-menu.php:1142
Maintenance & Trust

SlickNav Mobile Menu Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 29, 2025
PHP min version
Downloads107K

Community Trust

Rating96/100
Number of ratings24
Active installs3K
Developer Profile

SlickNav Mobile Menu Developer Profile

neilgee

8 plugins · 9K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
396 days
View full developer profile
Detection Fingerprints

How We Detect SlickNav Mobile Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/slicknav-mobile-menu/js/jquery.slicknav.min.js/wp-content/plugins/slicknav-mobile-menu/js/velocity.min.js/wp-content/plugins/slicknav-mobile-menu/css/slicknav.min.css/wp-content/plugins/slicknav-mobile-menu/js/slick-init.js
Script Paths
/wp-content/plugins/slicknav-mobile-menu/js/jquery.slicknav.min.js/wp-content/plugins/slicknav-mobile-menu/js/velocity.min.js/wp-content/plugins/slicknav-mobile-menu/js/slick-init.js
Version Parameters
/wp-content/plugins/slicknav-mobile-menu/js/jquery.slicknav.min.js?ver=/wp-content/plugins/slicknav-mobile-menu/js/velocity.min.js?ver=/wp-content/plugins/slicknav-mobile-menu/css/slicknav.min.css?ver=/wp-content/plugins/slicknav-mobile-menu/js/slick-init.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- SlickNav Mobile Menu --><!-- SlickNav Mobile Menu Options --><!-- SlickNav Menu --><!-- SlickNav Options Plugin -->+10 more
Data Attributes
data-slicknav-activedata-slicknav-searchdata-slicknav-labeldata-slicknav-menudata-slicknav-branddata-slicknav-position+11 more
JS Globals
slickNavVars
FAQ

Frequently Asked Questions about SlickNav Mobile Menu