Vertical Image Menu Security & Risk Analysis

wordpress.org/plugins/vertical-image-menu

This wordpress plugin provides a shortcode to add a vertical scrolling image or icon menu.

10 active installs v1.0.1 PHP + WP 3.1+ Updated Mar 13, 2012
bmo-designimagemenuscrollvertical
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Vertical Image Menu Safe to Use in 2026?

Generally Safe

Score 85/100

Vertical Image Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The vertical-image-menu plugin v1.0.1 exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the lack of file operations or external HTTP requests are commendable security practices. However, a significant concern arises from the low rate of output escaping, with only 33% of outputs being properly sanitized. This leaves room for potential Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered without adequate escaping.

The plugin has no recorded vulnerability history, which is a strong indicator of past good security practices. The lack of identified taint flows and the zero count of unpatched CVEs further reinforce this. Despite the strong foundation, the incomplete output escaping presents a tangible risk that should not be overlooked. Therefore, while the plugin demonstrates strengths in core areas, the potential for XSS due to insufficient output sanitization is its primary weakness.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Vertical Image Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Vertical Image Menu Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Vertical Image Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped6 total outputs
Attack Surface

Vertical Image Menu Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[verticalImageMenu] verticalImageMenu.php:149
[verticalimagemenu] verticalImageMenu.php:150
WordPress Hooks 5
actionadmin_menuverticalImageMenu.php:144
actionadmin_initverticalImageMenu.php:145
filterplugin_row_metaverticalImageMenu.php:146
actionwp_enqueue_scriptsverticalImageMenu.php:153
actionwp_headverticalImageMenu.php:154
Maintenance & Trust

Vertical Image Menu Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedMar 13, 2012
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Vertical Image Menu Developer Profile

Benedikt Mo

2 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Vertical Image Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vertical-image-menu/verticalImageMenu.css
Script Paths
/wp-content/plugins/vertical-image-menu/js/jquery.scrollTo.js/wp-content/plugins/vertical-image-menu/js/verticalImageMenu.js
Version Parameters
vertical-image-menu/verticalImageMenu.css?ver=1.0.1

HTML / DOM Fingerprints

CSS Classes
vertical_imagemenu
HTML Comments
<!-- Vertical Image Menu 1.0.1 -->
JS Globals
vimSpeed
FAQ

Frequently Asked Questions about Vertical Image Menu