
WP Master Business Menu Security & Risk Analysis
wordpress.org/plugins/wp-master-business-menuWP Master Business Menu allows you to create a simple and modern looking menu. This is great for displaying restaurant menus, venue events and much mo …
Is WP Master Business Menu Safe to Use in 2026?
Generally Safe
Score 85/100WP Master Business Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-master-business-menu" plugin, version 1.0.1, exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, and file operations is a positive indicator. Crucially, all identified SQL queries utilize prepared statements, and there's a single instance of a nonce check and a capability check, suggesting some attempt at securing entry points. The vulnerability history is also clean, with no known CVEs, indicating a potentially well-maintained codebase or a lack of prior significant discoveries.
However, there are notable areas of concern. The low percentage of properly escaped output (20%) represents a significant risk. This indicates that a substantial amount of data processed and displayed by the plugin may be vulnerable to Cross-Site Scripting (XSS) attacks. While the attack surface is small and technically has no unprotected entry points, the lack of robust output sanitization for the majority of outputs undermines this. The taint analysis reporting zero flows is positive, but it could also be a result of limited scope or the specific nature of the code that did not trigger taint detection.
In conclusion, while the plugin benefits from the absence of critical vulnerabilities and a secure approach to database queries, the widespread lack of output escaping is a serious weakness that could be exploited. Users should be aware of the potential for XSS vulnerabilities. The clean vulnerability history is a good sign, but it should not overshadow the identified code-level risks.
Key Concerns
- Low output escaping percentage (20%)
WP Master Business Menu Security Vulnerabilities
WP Master Business Menu Release Timeline
WP Master Business Menu Code Analysis
Output Escaping
WP Master Business Menu Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
WP Master Business Menu Maintenance & Trust
Maintenance Signals
Community Trust
WP Master Business Menu Alternatives
Restaurant Menu – Food Ordering System – Table Reservation
menu-ordering-reservations
Create a restaurant menu and start taking food orders online, with no commissions or costs. Table reservations are also available for free.
Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin
orderable
Take your restaurant/food business online with the online ordering system plugin for WordPress, Orderable.
Food Menu – Restaurant Menu & Online Ordering for WooCommerce
tlp-food-menu
A Simple Food & Restaurant Menu Display Plugin for Restaurant, Cafes, Fast Food, Coffee House with WooCommerce Online Ordering.
Restaurant Menu and Food Ordering
mp-restaurant-menu
Create and maintain modern online menus for almost any kind of restaurant. Sell food and beverages online. All in one plugin.
Great Restaurant Menu WP
best-restaurant-menu-by-pricelisto
The fastest and easiest way to create a professional-looking menu or price list for your restaurant or business.
WP Master Business Menu Developer Profile
8 plugins · 470 total installs
How We Detect WP Master Business Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-master-business-menu/admin/css/wpm-business-menu-admin.css/wp-content/plugins/wp-master-business-menu/admin/js/wpm-business-menu-admin.js/wp-content/plugins/wp-master-business-menu/admin/js/wpm-business-menu-admin.jswp-master-business-menu/admin/css/wpm-business-menu-admin.css?ver=wp-master-business-menu/admin/js/wpm-business-menu-admin.js?ver=HTML / DOM Fingerprints
wpm-business-menu-adminwpm_business_menu_itemsdata-post-id