WP Top Navigation Security & Risk Analysis

wordpress.org/plugins/wp-top-navigation

Puts the WordPress admin navigation at the top of the screen providing more screen estate for the rest of WordPress.

10 active installs v1.4.0 PHP + WP 3.8+ Updated Apr 24, 2015
navigationscrolltop
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Top Navigation Safe to Use in 2026?

Generally Safe

Score 85/100

WP Top Navigation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "wp-top-navigation" plugin version 1.4.0 exhibits a very strong security posture. The code analysis reveals no dangerous functions, no unescaped output, no file operations, and no external HTTP requests, all of which are excellent indicators of secure coding practices. Furthermore, all SQL queries are properly prepared, and there are no identified taint flows indicating potential injection vulnerabilities. The plugin also demonstrates a minimal attack surface with zero AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, none of these entry points appear to be unprotected.

The vulnerability history further reinforces this positive assessment, with no known CVEs recorded for this plugin. This lack of historical vulnerabilities suggests consistent security awareness and maintenance by the developers. However, it's important to note that the absence of nonce and capability checks on the identified entry points (though there are none) could become a concern if new functionality is added without these essential security layers. Despite this minor observation, the current version appears to be highly secure and unlikely to pose significant risks to a WordPress site.

Vulnerabilities
None known

WP Top Navigation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Top Navigation Release Timeline

v1.4.0Current
v1.2.1
Code Analysis
Analyzed Apr 16, 2026

WP Top Navigation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP Top Navigation Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedtrunk/wp-top-navigation.php:31
actionadmin_enqueue_scriptstrunk/wp-top-navigation.php:50
filteradmin_body_classtrunk/wp-top-navigation.php:68
actionplugins_loadedwp-top-navigation.php:31
actionadmin_enqueue_scriptswp-top-navigation.php:50
filteradmin_body_classwp-top-navigation.php:68
Maintenance & Trust

WP Top Navigation Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedApr 24, 2015
PHP min version
Downloads7K

Community Trust

Rating90/100
Number of ratings2
Active installs10
Developer Profile

WP Top Navigation Developer Profile

Stew Dellow

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Top Navigation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-top-navigation/js/navigation.js/wp-content/plugins/wp-top-navigation/css/wp-admin.css/wp-content/plugins/wp-top-navigation/css/admin-bar.css/wp-content/plugins/wp-top-navigation/css/wp-top-navigation.css/wp-content/plugins/wp-top-navigation/css/colors/dummy.css
Script Paths
/wp-content/plugins/wp-top-navigation/js/navigation.js
Version Parameters
wp-top-navigation/js/navigation.js?ver=wp-top-navigation/css/wp-admin.css?ver=wp-top-navigation/css/admin-bar.css?ver=wp-top-navigation/css/wp-top-navigation.css?ver=wp-top-navigation/css/colors/dummy.css?ver=

HTML / DOM Fingerprints

CSS Classes
wp-top-navigation-slider
JS Globals
wp_top_navigation_vars
FAQ

Frequently Asked Questions about WP Top Navigation