
Wizhi Submenus Security & Risk Analysis
wordpress.org/plugins/wizhi-submenusDisplay page`s subpage and taxonomy terms belongs to a post type in sidebar,在侧边栏显示某个页面的子页面列表或隶属于某个文章类型下面的自定义分类项目列表。
Is Wizhi Submenus Safe to Use in 2026?
Generally Safe
Score 85/100Wizhi Submenus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wizhi-submenus v3.3.5 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate a commendable adherence to secure coding practices, with no dangerous functions detected, all SQL queries utilizing prepared statements, and no file operations or external HTTP requests. The lack of any recorded vulnerabilities (CVEs) in its history is also a positive indicator of past security diligence.
However, there are a few areas that warrant attention and represent potential concerns. The most significant is the remarkably low percentage of properly escaped output (10%). With 40 total outputs analyzed, this means that 36 outputs are not being properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if any of the data processed or displayed by these outputs originates from an untrusted source. The complete absence of nonce checks and capability checks, while seemingly justified by the minimal attack surface, could become a weakness if new entry points are introduced in future updates without proper security considerations. In conclusion, while the plugin is currently robust due to its limited attack surface and good SQL practices, the widespread unescaped output is a notable risk that should be addressed to ensure comprehensive security.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Wizhi Submenus Security Vulnerabilities
Wizhi Submenus Code Analysis
Output Escaping
Wizhi Submenus Attack Surface
WordPress Hooks 2
Maintenance & Trust
Wizhi Submenus Maintenance & Trust
Maintenance Signals
Community Trust
Wizhi Submenus Alternatives
Themebeez Toolkit
themebeez-toolkit
A essential toolkit for WordPress themes developed by us. Themebeez Toolkit helps you to import dummy demo contents. It also adds extra features & …
Widgets in Menu for WordPress
widgets-in-menu
Allows you to add Widgets in WordPress Navigation Menus
Editor Menu and Widget Access
editor-menu-and-widget-access
Allow and control Editor and Shop Manager access to the menus, widgets and appearance menu, plus other menus and adminbar items.
Everest Toolkit
everest-toolkit
A essential toolkit for themes made by everestthemes (everestthemes.com). Everest toolkit helps you to setup your website or blog faster.
Off-Canvas Sidebars & Menus (Slidebars)
off-canvas-sidebars
Add off-canvas sidebars (Slidebars) containing widgets, menus or other content using the Slidebars jQuery plugin.
Wizhi Submenus Developer Profile
8 plugins · 5K total installs
How We Detect Wizhi Submenus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
rs-submenu__listid="wizhi-submenus-widget-custom-css"