
WPML flag in menu Extended Security & Risk Analysis
wordpress.org/plugins/wpml-flag-in-menu-extendedShows flags of WPML translated content in selected menu's
Is WPML flag in menu Extended Safe to Use in 2026?
Generally Safe
Score 85/100WPML flag in menu Extended has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wpml-flag-in-menu-extended" v1.7 plugin exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, cron events, dangerous functions, raw SQL queries, file operations, external HTTP requests, nonce checks, and capability checks indicates a well-contained plugin with a minimal attack surface. The taint analysis revealing zero flows with unsanitized paths further reinforces this positive assessment, suggesting no immediate risks of code injection or data manipulation through tainted input.
However, a significant concern arises from the output escaping. With 33% of outputs properly escaped out of 12 total outputs, this leaves a considerable portion (approximately 8 outputs) potentially vulnerable to Cross-Site Scripting (XSS) attacks. While the plugin has no recorded CVEs and a clean vulnerability history, this lack of robust output sanitization presents a tangible risk that could be exploited by attackers to inject malicious scripts into the website.
In conclusion, the plugin's design demonstrates excellent practices in preventing common vulnerabilities like SQL injection and unauthorized access. The lack of recorded historical vulnerabilities is a positive indicator. Nevertheless, the unaddressed output escaping is a critical weakness that significantly impacts its overall security. While the attack surface is commendably small, the potential for XSS through unescaped output warrants attention and mitigation.
Key Concerns
- Low percentage of properly escaped output
WPML flag in menu Extended Security Vulnerabilities
WPML flag in menu Extended Code Analysis
Output Escaping
WPML flag in menu Extended Attack Surface
WordPress Hooks 6
Maintenance & Trust
WPML flag in menu Extended Maintenance & Trust
Maintenance Signals
Community Trust
WPML flag in menu Extended Alternatives
WPML flag in menu
wpml-flag-in-menu
Shows translated flags (for every language except current viewing lang) in the default or wp_nav_menu at last position
Oceanwp sticky header
sticky-header-oceanwp
Easy Sticky header installation
Add menu separators to navigation
mhm-menu-separator
Allow separator (HR / line) and unlinked, text-only entries in WordPress' classic navigation menus.
Disable Parent Menu Link
disable-parent-menu-link
A plugin which allows you to disable parent menu link created through wp_nav_menu function.
Sticky Elementor – Sticky Header, Menu Color After Sticky, Logo Swap & Back to Top Button
sticky-elementor
Free Sticky Header for Elementor. Features Logo Swap, Shrink Effect, Mobile Sticky Menu, Scroll Blur, and Zero Layout Shift. No Pro Required!
WPML flag in menu Extended Developer Profile
4 plugins · 340 total installs
How We Detect WPML flag in menu Extended
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpml-flag-in-menu-extended/css/admin.css/wp-content/plugins/wpml-flag-in-menu-extended/css/style.csswpml-flag-in-menu-extended/css/admin.css?ver=wpml-flag-in-menu-extended/css/style.css?ver=HTML / DOM Fingerprints
wpml-flag-in-menu-extended_stylingwpml-flag-in-menu-extended_basicsflag_wrap_tagflag_wrap_classWPML_Flags_extended[wpml_flag_menu]