Access Keys for WP Navigation Menus Security & Risk Analysis

wordpress.org/plugins/wordpress-nav-menus-access-keys

Add Access Keys to WordPress 3.6 Nav menus to make your website far more accessible.

70 active installs v1.6 PHP + WP 3.3+ Updated Oct 18, 2013
access-keysaccessibilityadmincategoriespages
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Access Keys for WP Navigation Menus Safe to Use in 2026?

Generally Safe

Score 85/100

Access Keys for WP Navigation Menus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'wordpress-nav-menus-access-keys' plugin v1.6 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals no dangerous functions, no raw SQL queries (all are prepared statements), no file operations, no external HTTP requests, and crucially, no unsanitized taint flows. This indicates a well-written and security-conscious codebase with regards to common attack vectors.

However, there is a notable concern regarding output escaping. The analysis shows one total output with 0% properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed directly without proper sanitization. While there are no recorded CVEs or historical vulnerabilities, this single unescaped output represents a potential, albeit likely low, risk that should be addressed. The plugin's strengths lie in its minimal attack surface and secure handling of SQL and taint flows. Its primary weakness, based on this data, is the unescaped output.

Key Concerns

  • Unescaped output found
Vulnerabilities
None known

Access Keys for WP Navigation Menus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Access Keys for WP Navigation Menus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Access Keys for WP Navigation Menus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_headnav_menu_access_keys.php:20
actionwp_update_nav_menu_itemnav_menu_access_keys.php:21
filterwalker_nav_menu_start_elnav_menu_access_keys.php:22
Maintenance & Trust

Access Keys for WP Navigation Menus Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedOct 18, 2013
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs70
Developer Profile

Access Keys for WP Navigation Menus Developer Profile

Aaron Butacov

6 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Access Keys for WP Navigation Menus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/wordpress-nav-menus-access-keys/nav_menu_access_keys.php

HTML / DOM Fingerprints

CSS Classes
edit-menu-item-attr-accesskey
Data Attributes
accesskey
JS Globals
keys
FAQ

Frequently Asked Questions about Access Keys for WP Navigation Menus