
WFK Menu Import/Export Security & Risk Analysis
wordpress.org/plugins/wfk-menu-importexportEasily export and import WordPress navigation menus. Backup, migrate, and transfer menus between sites using a simple JSON file.
Is WFK Menu Import/Export Safe to Use in 2026?
Generally Safe
Score 100/100WFK Menu Import/Export has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wfk-menu-importexport" plugin v1.1.0 demonstrates a generally good security posture based on the provided static analysis. It has a limited attack surface with all identified AJAX handlers performing nonce checks. The absence of shortcodes, cron events, and REST API routes further minimizes potential entry points. Crucially, the plugin utilizes prepared statements for all its SQL queries and has a high percentage of properly escaped output, indicating a strong focus on preventing common web vulnerabilities like SQL injection and cross-site scripting (XSS). The lack of any recorded vulnerabilities in its history is also a positive sign, suggesting a history of secure development. However, the presence of two 'unserialize' function calls is a notable concern. While not directly flagged in the taint analysis (which found no unsanitized paths), the unserialize function is inherently risky as it can lead to arbitrary code execution if processing untrusted data. Further investigation into how these unserialize calls are used and whether the data they process is strictly validated and sanitized is recommended. The single external HTTP request also warrants scrutiny to ensure it's not leading to any supply chain risks.
Key Concerns
- Use of unserialize function
- External HTTP request without context
WFK Menu Import/Export Security Vulnerabilities
WFK Menu Import/Export Release Timeline
WFK Menu Import/Export Code Analysis
Dangerous Functions Found
Output Escaping
WFK Menu Import/Export Attack Surface
AJAX Handlers 3
WordPress Hooks 12
Maintenance & Trust
WFK Menu Import/Export Maintenance & Trust
Maintenance Signals
Community Trust
WFK Menu Import/Export Alternatives
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Admin Menu Editor
admin-menu-editor
Lets you edit the WordPress admin menu. You can re-order, hide or rename menus, add custom menus and more.
Happy Addons for Elementor
happy-elementor-addons
HappyAddons for Elementor-Get Header Footer, Single Post, Archive Page, Megamenu, Slider Builder & 143 Elementor Widgets.
Max Mega Menu
megamenu
An easy to use mega menu plugin. Written the WordPress way.
WFK Menu Import/Export Developer Profile
2 plugins · 10 total installs
How We Detect WFK Menu Import/Export
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wfk-menu-importexport/assets/css/wfktyh-mie-style.css/wp-content/plugins/wfk-menu-importexport/assets/js/wfktyh-mie-script.js/wp-content/plugins/wfk-menu-importexport/assets/js/wfktyh-mie-script.jswfk-menu-importexport/assets/css/wfktyh-mie-style.css?ver=wfk-menu-importexport/assets/js/wfktyh-mie-script.js?ver=HTML / DOM Fingerprints
wfp_menu_import_export_containerwfktyh_mie_vars