WP Master Business Menu Security & Risk Analysis

wordpress.org/plugins/wp-master-business-menu

WP Master Business Menu allows you to create a simple and modern looking menu. This is great for displaying restaurant menus, venue events and much mo …

10 active installs v1.0.1 PHP + WP 3.7+ Updated May 15, 2017
business-menufood-menumenurestaurant-menuservice-menu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Master Business Menu Safe to Use in 2026?

Generally Safe

Score 85/100

WP Master Business Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "wp-master-business-menu" plugin, version 1.0.1, exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, and file operations is a positive indicator. Crucially, all identified SQL queries utilize prepared statements, and there's a single instance of a nonce check and a capability check, suggesting some attempt at securing entry points. The vulnerability history is also clean, with no known CVEs, indicating a potentially well-maintained codebase or a lack of prior significant discoveries.

However, there are notable areas of concern. The low percentage of properly escaped output (20%) represents a significant risk. This indicates that a substantial amount of data processed and displayed by the plugin may be vulnerable to Cross-Site Scripting (XSS) attacks. While the attack surface is small and technically has no unprotected entry points, the lack of robust output sanitization for the majority of outputs undermines this. The taint analysis reporting zero flows is positive, but it could also be a result of limited scope or the specific nature of the code that did not trigger taint detection.

In conclusion, while the plugin benefits from the absence of critical vulnerabilities and a secure approach to database queries, the widespread lack of output escaping is a serious weakness that could be exploited. Users should be aware of the potential for XSS vulnerabilities. The clean vulnerability history is a good sign, but it should not overshadow the identified code-level risks.

Key Concerns

  • Low output escaping percentage (20%)
Vulnerabilities
None known

WP Master Business Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Master Business Menu Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

WP Master Business Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
3 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped15 total outputs
Attack Surface

WP Master Business Menu Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wpm-business-menu] public/class-wpm-business-menu-public.php:87
WordPress Hooks 11
actionplugins_loadedincludes/class-wpm-business-menu.php:139
actionadmin_enqueue_scriptsincludes/class-wpm-business-menu.php:154
actionadmin_enqueue_scriptsincludes/class-wpm-business-menu.php:155
actionadmin_menuincludes/class-wpm-business-menu.php:156
actioninitincludes/class-wpm-business-menu.php:157
actionadd_meta_boxesincludes/class-wpm-business-menu.php:158
actionsave_post_wpm_business_menuincludes/class-wpm-business-menu.php:159
filtermanage_wpm_business_menu_posts_columnsincludes/class-wpm-business-menu.php:160
actionmanage_wpm_business_menu_posts_custom_columnincludes/class-wpm-business-menu.php:161
actionwp_enqueue_scriptsincludes/class-wpm-business-menu.php:176
actioninitincludes/class-wpm-business-menu.php:177
Maintenance & Trust

WP Master Business Menu Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedMay 15, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP Master Business Menu Developer Profile

WebSPI

8 plugins · 470 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Master Business Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-master-business-menu/admin/css/wpm-business-menu-admin.css/wp-content/plugins/wp-master-business-menu/admin/js/wpm-business-menu-admin.js
Script Paths
/wp-content/plugins/wp-master-business-menu/admin/js/wpm-business-menu-admin.js
Version Parameters
wp-master-business-menu/admin/css/wpm-business-menu-admin.css?ver=wp-master-business-menu/admin/js/wpm-business-menu-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpm-business-menu-adminwpm_business_menu_items
Data Attributes
data-post-id
FAQ

Frequently Asked Questions about WP Master Business Menu