VertiMenu Security & Risk Analysis

wordpress.org/plugins/vertimenu

Multilevel mobile menu with optional third-party menu item image support.

0 active installs v1.1.1 PHP + WP 4.5+ Updated Dec 8, 2018
menumobile-menumultilevelmultilevel-menuvertimenu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is VertiMenu Safe to Use in 2026?

Generally Safe

Score 85/100

VertiMenu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin "vertimenu" v1.1.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any discovered AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests, all of which are excellent security practices. The high percentage of properly escaped output is also a positive indicator, reducing the risk of cross-site scripting (XSS) vulnerabilities.

However, there are a couple of areas that warrant attention. The complete lack of nonce checks and capability checks across all entry points, although the entry points themselves are currently zero, represents a potential future risk. If new entry points are introduced or if existing ones are modified without proper authentication and authorization mechanisms, vulnerabilities could easily arise. The zero taint analysis flows are encouraging, but this is likely due to the limited attack surface and absence of user-controllable input processing. The plugin's vulnerability history is also clean, with no recorded CVEs, which is a strong testament to its current security. In conclusion, while "vertimenu" v1.1.1 is currently in a very secure state due to its minimal attack surface and good coding practices, the absence of authorization checks presents a latent risk that should be addressed if the plugin's functionality expands.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • Low output escaping coverage (21% unescaped)
Vulnerabilities
None known

VertiMenu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

VertiMenu Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

VertiMenu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
19 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

79% escaped24 total outputs
Attack Surface

VertiMenu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioncustomize_registervertimenu.php:118
actioninitvertimenu.php:265
actioninitvertimenu.php:266
actioninitvertimenu.php:267
actioncustomize_registervertimenu.php:269
actioncustomize_controls_print_stylesvertimenu.php:270
actionwp_footervertimenu.php:272
actionwp_footervertimenu.php:273
Maintenance & Trust

VertiMenu Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 8, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

VertiMenu Developer Profile

sagaio

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect VertiMenu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vertimenu/js/vertimenu.js/wp-content/plugins/vertimenu/css/vertimenu.css
Script Paths
/wp-content/plugins/vertimenu/js/vertimenu.js
Version Parameters
vertimenu/style.css?ver=vertimenu/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
vertimenu-submenuvertimenu-menu-itemvertimenu-menu-item-has-image
Data Attributes
data-sagaio_vertimenu_menu_item_indicator_icon_right
JS Globals
sagaio_vertimenu_item_with_subitems_clickable
FAQ

Frequently Asked Questions about VertiMenu