
User Links for WP Menus Security & Risk Analysis
wordpress.org/plugins/user-links-for-wp-menusAdds a metabox to the menu admin page listing users so they can be more easily added as custom links to the WordPress Custom Menus
Is User Links for WP Menus Safe to Use in 2026?
Generally Safe
Score 100/100User Links for WP Menus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'user-links-for-wp-menus' plugin, in version 0.2, exhibits a mixed security posture. On the positive side, the static analysis reveals no direct entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are exposed. Furthermore, there are no identified dangerous functions, file operations, external HTTP requests, or bundled libraries, which reduces the potential attack surface. The single SQL query observed is commendably using prepared statements, a strong security practice.
However, significant concerns arise from the output escaping. With 7 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed by the plugin is likely vulnerable to injection. The complete absence of nonce checks and capability checks, especially given the potential for user interaction even without explicit entry points, is also a significant weakness. The lack of any recorded vulnerability history suggests either a history of good security or a lack of scrutiny, but the current code analysis points to a clear and present danger with unescaped output.
In conclusion, while the plugin avoids many common pitfalls by having a limited attack surface and using prepared statements for its SQL query, the critical flaw in output escaping makes it highly susceptible to XSS attacks. The absence of authorization checks further exacerbates this risk. The vulnerability history being clear is a positive sign, but it does not mitigate the severe issues identified in the current code analysis.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
User Links for WP Menus Security Vulnerabilities
User Links for WP Menus Code Analysis
SQL Query Safety
Output Escaping
User Links for WP Menus Attack Surface
WordPress Hooks 1
Maintenance & Trust
User Links for WP Menus Maintenance & Trust
Maintenance Signals
Community Trust
User Links for WP Menus Alternatives
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
Smart User Slug Hider
smart-user-slug-hider
Hide usernames in Author Pages URLs to enhance Security
Simple User Listing
simple-user-listing
A shortcode for displaying paginated lists of users.
Smart Custom Display Name
smart-custom-display-name
Allows you to change the value of "Display name publicly as" in user profiles to any string
User Links for WP Menus Developer Profile
1 plugin · 10 total installs
How We Detect User Links for WP Menus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
userlinks-menu-metaboxuserlinks-checklistid="userlinks-menu-metabox"id="tabs-panel-users"id="userlinks-checklist"class="menu-item-checkbox"name="menu-item[-.*][menu-item-object-id]"class="menu-item-type"+6 more