Vertical Menu Widget Security & Risk Analysis

wordpress.org/plugins/vertical-menu-widget

Easily add a vertical menu to your widgetable sidebar. With this plugin you can create a simple/flat menu or a foldout menu.

100 active installs v0.9 PHP + WP 3.0.1+ Updated Jun 20, 2011
foldout-menuvertical-menu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Vertical Menu Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Vertical Menu Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

Based on the provided static analysis, the "vertical-menu-widget" plugin v0.9 exhibits a strong security posture. The absence of any detected dangerous functions, raw SQL queries, or unescaped output suggests that the developers have implemented robust coding practices. Furthermore, the plugin demonstrates zero external HTTP requests and no file operations, which significantly reduces the attack surface. The lack of identified vulnerabilities in the vulnerability history, including no recorded CVEs or common vulnerability types, further reinforces this positive assessment.

While the plugin's current state appears very secure with no immediate threats identified, the analysis reveals a complete absence of any protection mechanisms like nonce checks or capability checks. This means that if any new entry points were introduced in future versions, they might be vulnerable if not properly secured. The plugin's low attack surface is a strength, but the lack of built-in security checks on any potential, even if currently non-existent, entry points is a notable weakness. Overall, the plugin is currently secure due to its limited functionality and good coding practices, but future development should prioritize adding appropriate security checks to maintain this posture.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Vertical Menu Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Vertical Menu Widget Release Timeline

v0.9Current
Code Analysis
Analyzed Mar 16, 2026

Vertical Menu Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Vertical Menu Widget Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Vertical Menu Widget Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedJun 20, 2011
PHP min version
Downloads15K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

Vertical Menu Widget Developer Profile

Daniel Iser

8 plugins · 827K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
588 days
View full developer profile
Detection Fingerprints

How We Detect Vertical Menu Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
childrenpage_itempage-itemactive
Data Attributes
class="page_item page-item-class="menu-item menuclass="active"
FAQ

Frequently Asked Questions about Vertical Menu Widget