
Super Admin All Sites Menu Security & Risk Analysis
wordpress.org/plugins/super-admin-all-sites-menuFor the super admin, replace WP Admin Bar My Sites menu with an All Sites menu.
Is Super Admin All Sites Menu Safe to Use in 2026?
Generally Safe
Score 100/100Super Admin All Sites Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "super-admin-all-sites-menu" v1.12.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, unsanitized taint flows, direct SQL queries without prepared statements, unescaped output, file operations, or external HTTP requests is commendable. The attack surface appears to be effectively managed with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack proper authorization or permission checks.
However, a notable concern arises from the complete lack of nonce checks. While capability checks are present, the absence of nonces on any potential entry points (even though none are explicitly identified as unprotected) can leave the application vulnerable to Cross-Site Request Forgery (CSRF) attacks if the attack surface expands or if the current assessment missed subtle entry points. The plugin's vulnerability history, being completely clear, is a positive indicator, suggesting good development practices and a lack of previously exploited weaknesses. Despite the clean history, the absence of nonce checks remains a critical omission that warrants attention for robust security.
In conclusion, the plugin demonstrates excellent code quality and a proactive approach to preventing common vulnerabilities. The secure handling of data, SQL, and output is a significant strength. Nevertheless, the lack of nonce checks represents a potential blind spot that could be exploited if the plugin were to gain additional interaction points or if an attacker finds a way to trigger actions without proper validation. Addressing this would elevate its security to an even higher standard.
Key Concerns
- Missing nonce checks
Super Admin All Sites Menu Security Vulnerabilities
Super Admin All Sites Menu Release Timeline
Super Admin All Sites Menu Code Analysis
SQL Query Safety
Output Escaping
Super Admin All Sites Menu Attack Surface
WordPress Hooks 13
Maintenance & Trust
Super Admin All Sites Menu Maintenance & Trust
Maintenance Signals
Community Trust
Super Admin All Sites Menu Alternatives
Delete Me
delete-me
Allow users with specific WordPress roles to delete themselves from the Your Profile page or anywhere Shortcodes can be used.
Multisite User Role Manager
multisite-user-role-manager
Manage user roles for each blog from a single screen on multisite (WPMU) setups
Network Plugin Auditor
network-plugin-auditor
For multisite/network installations only. Adds columns to your network admin to show which sites are using each plugin and theme.
Multisite Usage Scanner
multisite-usage-scanner
Scan your WordPress multisite network to identify which plugins are actively used across sites. Helps admins safely clean up unused plugins.
Rootscope Remote Site Manager
rootscope-remote-site-manager
Connect your WordPress site to wp-admin.online remote Site Manager for centralized management.
Super Admin All Sites Menu Developer Profile
102 plugins · 177K total installs
How We Detect Super Admin All Sites Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/super-admin-all-sites-menu/admin.css/wp-content/plugins/super-admin-all-sites-menu/admin.js/wp-content/plugins/super-admin-all-sites-menu/admin.jssuper-admin-all-sites-menu/admin.css?ver=super-admin-all-sites-menu/admin.js?ver=HTML / DOM Fingerprints
my-sites-containerall-sites-search-wrapperall-sites-listid="all-sites-search-text"placeholder="Filter My Sites"window.superAdminAllSitesMenu/wp-json/super-admin-all-sites-menu/v1/sites