
VertiMenu Security & Risk Analysis
wordpress.org/plugins/vertimenuMultilevel mobile menu with optional third-party menu item image support.
Is VertiMenu Safe to Use in 2026?
Generally Safe
Score 85/100VertiMenu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "vertimenu" v1.1.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any discovered AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests, all of which are excellent security practices. The high percentage of properly escaped output is also a positive indicator, reducing the risk of cross-site scripting (XSS) vulnerabilities.
However, there are a couple of areas that warrant attention. The complete lack of nonce checks and capability checks across all entry points, although the entry points themselves are currently zero, represents a potential future risk. If new entry points are introduced or if existing ones are modified without proper authentication and authorization mechanisms, vulnerabilities could easily arise. The zero taint analysis flows are encouraging, but this is likely due to the limited attack surface and absence of user-controllable input processing. The plugin's vulnerability history is also clean, with no recorded CVEs, which is a strong testament to its current security. In conclusion, while "vertimenu" v1.1.1 is currently in a very secure state due to its minimal attack surface and good coding practices, the absence of authorization checks presents a latent risk that should be addressed if the plugin's functionality expands.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Low output escaping coverage (21% unescaped)
VertiMenu Security Vulnerabilities
VertiMenu Release Timeline
VertiMenu Code Analysis
Output Escaping
VertiMenu Attack Surface
WordPress Hooks 8
Maintenance & Trust
VertiMenu Maintenance & Trust
Maintenance Signals
Community Trust
VertiMenu Alternatives
Multilevel Navigation Menu
multilevel-navigation-menu
Multilevel Navigation Menu plugin ability to add a full-screen navigation menu to our website.
Max Mega Menu
megamenu
An easy to use mega menu plugin. Written the WordPress way.
WP Mobile Menu – The Mobile-Friendly Responsive Menu
mobile-menu
Need some help with the mobile website experience? Need an Mobile Menu plugin that keep your mobile visitors engaged?
WP Bottom Menu
wp-bottom-menu
WP Bottom Menu allows you to add a woocommerce supported bottom menu to your site.
WP Mobile Bottom Menu
mobile-bottom-menu-for-wp
Smooth Navigation for Mobile. Create an Eye-Catching Sticky Bottom Menu with Limitless Customization Options.
VertiMenu Developer Profile
2 plugins · 20 total installs
How We Detect VertiMenu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vertimenu/js/vertimenu.js/wp-content/plugins/vertimenu/css/vertimenu.css/wp-content/plugins/vertimenu/js/vertimenu.jsvertimenu/style.css?ver=vertimenu/script.js?ver=HTML / DOM Fingerprints
vertimenu-submenuvertimenu-menu-itemvertimenu-menu-item-has-imagedata-sagaio_vertimenu_menu_item_indicator_icon_rightsagaio_vertimenu_item_with_subitems_clickable