Taxonomy Submenu Security & Risk Analysis

wordpress.org/plugins/taxonomy-submenu

A Gutenberg block that creates dynamic submenu items from any taxonomy and offers complete styling control beyond the default WordPress submenu block.

0 active installs v1.0.1 PHP 7.4+ WP 6.1+ Updated Dec 31, 2025
blockgutenbergmenunavigationtaxonomy
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Taxonomy Submenu Safe to Use in 2026?

Generally Safe

Score 100/100

Taxonomy Submenu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "taxonomy-submenu" plugin v1.0.1 demonstrates a strong security posture based on the provided static analysis. The complete absence of any identified attack surface points, dangerous functions, or raw SQL queries is highly commendable. Furthermore, the 100% proper output escaping and the use of prepared statements for all SQL queries indicate diligent secure coding practices. The plugin also has no recorded vulnerability history, which is a positive sign.

However, the complete lack of nonce checks and capability checks across all potential entry points, while currently yielding no identified vulnerabilities, represents a significant potential weakness. If the plugin were to introduce any functionality that processes user input or modifies data in the future, this absence of checks could easily lead to security issues. The zero taint analysis flows are also good, but could be attributed to the limited attack surface and lack of user-facing features, rather than inherently secure handling of all possible data flows.

In conclusion, the plugin is currently secure due to its limited functionality and robust basic secure coding practices. The main concern lies in the lack of implemented authorization and nonce checks, which creates a potential for future vulnerabilities should the plugin evolve or if its current (minimal) functionality were to be exploited in ways not immediately apparent from this analysis. The absence of any historical vulnerabilities is a strength, but the lack of built-in protective mechanisms is a weakness.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Taxonomy Submenu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Taxonomy Submenu Release Timeline

No version history available.
Code Analysis
Analyzed Apr 6, 2026

Taxonomy Submenu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
34 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped34 total outputs
Attack Surface

Taxonomy Submenu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninittaxonomy-submenu.php:45
actioninittaxonomy-submenu.php:55
Maintenance & Trust

Taxonomy Submenu Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 31, 2025
PHP min version7.4
Downloads147

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Taxonomy Submenu Developer Profile

ahmedgagankodyt

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Taxonomy Submenu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/taxonomy-submenu/build/index.js/wp-content/plugins/taxonomy-submenu/build/style-index.css
Script Paths
/wp-content/plugins/taxonomy-submenu/build/index.js
Version Parameters
taxonomy-submenu/build/index.js?ver=taxonomy-submenu/build/style-index.css?ver=

HTML / DOM Fingerprints

CSS Classes
taxonomy-submenuwp-block-navigation-itemhas-childopen-on-hover-clickwp-block-navigation-submenu
Data Attributes
data-block="taxonomy-submenu/taxonomy-submenu"
FAQ

Frequently Asked Questions about Taxonomy Submenu