
WP Home Page Menu Security & Risk Analysis
wordpress.org/plugins/wp-home-page-menuThis plugin displays home page menu in the navigation bar which can be configured easily from the admin area.
Is WP Home Page Menu Safe to Use in 2026?
Generally Safe
Score 85/100WP Home Page Menu has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-home-page-menu" v3.1 plugin presents a mixed security posture. On the positive side, it utilizes prepared statements for all SQL queries, has no identified file operations or external HTTP requests, and no bundled libraries, which are good security practices. However, there are significant concerns regarding its attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks, creating a direct avenue for unauthenticated attackers to interact with the plugin's functionality. The absence of nonce checks on these AJAX handlers further exacerbates this risk, making them susceptible to Cross-Site Request Forgery (CSRF) attacks.
The vulnerability history indicates a past Cross-Site Scripting (XSS) vulnerability, and while there are no currently unpatched CVEs, this history suggests a potential for input sanitization issues. The static analysis also shows that a considerable portion (39%) of output is not properly escaped, which could lead to XSS vulnerabilities if user-controlled data is displayed without adequate sanitization.
In conclusion, while the plugin demonstrates strengths in its handling of database queries and avoiding risky dependencies, the unprotected AJAX endpoints and unescaped output represent significant security weaknesses that an attacker could exploit. The past XSS vulnerability reinforces the need for careful input validation and output escaping.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX handlers
- Unescaped output
- Past XSS vulnerability
WP Home Page Menu Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Home Page Menu < 3.1 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Home Page Menu Code Analysis
Output Escaping
WP Home Page Menu Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
WP Home Page Menu Maintenance & Trust
Maintenance Signals
Community Trust
WP Home Page Menu Alternatives
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Admin Menu Editor
admin-menu-editor
Lets you edit the WordPress admin menu. You can re-order, hide or rename menus, add custom menus and more.
Happy Addons for Elementor
happy-elementor-addons
HappyAddons for Elementor-Get Header Footer, Single Post, Archive Page, Megamenu, Slider Builder & 143 Elementor Widgets.
Max Mega Menu
megamenu
An easy to use mega menu plugin. Written the WordPress way.
WP Home Page Menu Developer Profile
1 plugin · 100 total installs
How We Detect WP Home Page Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-home-page-menu/js/wp-home-page-menu-admin.js/wp-content/plugins/wp-home-page-menu/js/wp-home-page-menu-admin.jsHTML / DOM Fingerprints
wp-home-page-menuwp_home_page_menu_optionsid="wp_home_page_menu_options"wp_home_page_menu