
WP Bottom Menu Security & Risk Analysis
wordpress.org/plugins/wp-bottom-menuWP Bottom Menu allows you to add a woocommerce supported bottom menu to your site.
Is WP Bottom Menu Safe to Use in 2026?
Generally Safe
Score 100/100WP Bottom Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-bottom-menu" plugin version 2.2.4 presents a seemingly strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are exclusively using prepared statements, and file operations and external HTTP requests are absent. The plugin also boasts a very low attack surface with no shortcodes, cron events, or direct AJAX/REST API endpoints exposed without authentication. The vulnerability history is also clean, with zero known CVEs, indicating a history of secure development or prompt patching by the developers.
However, a significant concern arises from the complete lack of nonce checks and capability checks. This suggests that any potential entry points, even if currently nonexistent, would be entirely unprotected against CSRF attacks or unauthorized access if they were to be introduced in the future. While the current output escaping is reasonably high at 77%, the remaining 23% could still pose a risk for stored or reflected XSS vulnerabilities if user-supplied data is involved in those unescaped outputs. The absence of any taint analysis flows could be due to the code structure or analysis limitations, but it means potential complex vulnerabilities might have been missed.
In conclusion, the plugin demonstrates good practices in preventing common vulnerabilities like SQL injection and direct file manipulation. The clean vulnerability history is a positive indicator. The primary weaknesses lie in the absence of essential security checks (nonces and capabilities) and a moderate percentage of unescaped output, which could become significant risks if the plugin's functionality expands or if the context of the unescaped outputs involves untrusted data.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
- 23% of output not properly escaped
WP Bottom Menu Security Vulnerabilities
WP Bottom Menu Code Analysis
Bundled Libraries
Output Escaping
WP Bottom Menu Attack Surface
WordPress Hooks 11
Maintenance & Trust
WP Bottom Menu Maintenance & Trust
Maintenance Signals
Community Trust
WP Bottom Menu Alternatives
WP Mobile Bottom Menu
mobile-bottom-menu-for-wp
Smooth Navigation for Mobile. Create an Eye-Catching Sticky Bottom Menu with Limitless Customization Options.
SureWP App-Style Bottom Menu
surewp-app-bottom-menu
Add an app-style bottom navigation menu optimized for mobile devices with WooCommerce cart integration and search modal.
Footer Fixed Menu — Customized Bottom Navigation
footer-fixed-menu-customized-bottom-navigation
A plugin to display a fixed footer menu with icons synced with your WordPress menu. Includes customizable colors and tooltip labels.
Max Mega Menu
megamenu
An easy to use mega menu plugin. Written the WordPress way.
WP Mobile Menu – The Mobile-Friendly Responsive Menu
mobile-menu
Need some help with the mobile website experience? Need an Mobile Menu plugin that keep your mobile visitors engaged?
WP Bottom Menu Developer Profile
4 plugins · 20K total installs
How We Detect WP Bottom Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-bottom-menu/assets/css/style.css/wp-content/plugins/wp-bottom-menu/assets/js/main.js/wp-content/plugins/wp-bottom-menu/inc/customizer/customizer-repeater/css/font-awesome.min.css/wp-content/plugins/wp-bottom-menu/assets/vendors/fontawesome/all.min.css/wp-content/plugins/wp-bottom-menu/assets/js/customizer.js/wp-content/plugins/wp-bottom-menu/assets/vendors/select2/select2.min.js/wp-content/plugins/wp-bottom-menu/assets/vendors/select2/select2.min.css/wp-content/plugins/wp-bottom-menu/assets/js/main.js/wp-content/plugins/wp-bottom-menu/assets/js/customizer.js/wp-content/plugins/wp-bottom-menu/assets/vendors/select2/select2.min.jswp-bottom-menu/style.css?ver=wp-bottom-menu/main.js?ver=wp-bottom-menu/customizer.js?ver=wp-bottom-menu/select2.min.js?ver=wp-bottom-menu/select2.min.css?ver=HTML / DOM Fingerprints
wp-bottom-menuwp-bottom-menu-select2data-choicedata-subtitledata-titledata-linkdata-idWPBM