Dashboard customization tools influence navigation, capability checks, menu visibility, redirects, and access to administrative screens. Admin Menu Editor version 1.15.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64688, confirming that the review focused on settings authorization, capability handling, menu configuration integrity, redirect behavior, and safe processing of custom labels, URLs, and icons.

Name ofAdmin Menu Editor
Version1.15.2
Active installations300,000+
DescriptionLets administrators reorder dashboard menus, change titles and icons, hide or move items, assign capability requirements, and add custom menu links.
SecuritySuccessfully tested for:
SQL Injection (SQLi)
Cross-Site Scripting (XSS) – Stored and Reflected
Cross-Site Request Forgery (CSRF)
Authentication Vulnerabilities
Authentication Bypass Exploits
Privilege Escalation
Buffer Overflow
Denial-of-Service (DoS) vectors
Data Leakage Vulnerabilities
Insecure Dependency Usage
Remote Code Execution (RCE) Risks
Unauthorized File Access
Insufficient Injection Protection
Information Disclosure via Misconfigured Endpoints
CleanTalk CertificationProudly earned the “Plugin Security Certification” (PSC) from CleanTalk, indicating adherence to stringent security standards.
Additional InformationUse Admin Menu Editor with confidence backed by the “Plugin Security Certification” (PSC). Keep capability requirements explicit, verify that hidden items do not replace authorization checks, and test role access after every menu change.
Plugin Security Certification by CleanTalk
Logo of the plugin

Join the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.

PSC by Cleantalk

Key Features

Admin Menu Editor lets administrators reorganize the WordPress dashboard menu and adjust titles, URLs, icons, CSS classes, visibility, and capability requirements. It can move items between menu levels and add custom links to internal or external destinations. Menu visibility improves the dashboard experience, while access to the underlying screens still depends on WordPress capabilities and each component’s own authorization checks.

Security Assurance

The CleanTalk Plugin Security Certification evaluation focused on authorization for menu changes, validation of custom URLs and labels, integrity of stored configuration, and correct handling of capability requirements. The review also considered redirects, multisite use, output escaping, settings requests, and the boundary between hiding navigation and enforcing access to administrative functions.

The plugin has been successfully tested for:

✅ Information Leakage Vulnerabilities

✅ SQL Injection Vulnerabilities

✅ Cross-Site Scripting (XSS) Attacks

✅ Cross-Site Request Forgery (CSRF) Attacks

✅ Authentication and Authentication Bypass Vulnerabilities

✅ Privilege Escalation Vulnerabilities

✅ Buffer Overflow Vulnerabilities

✅ Denial-of-Service (DoS) Vulnerabilities

✅ Data Leakage Vulnerabilities

✅ Insecure Dependencies

✅ Code Execution Vulnerabilities

✅ File Unauthorized Access Vulnerabilities

✅ Insufficient Injection Protection

Conclusion

With PSC-2026-64688, Admin Menu Editor version 1.15.2 demonstrates strong baseline security for dashboard menu customization workflows. The certification addresses settings access, capability handling, custom URLs, stored menu data, and administrative redirects. Site owners should treat menu hiding as an interface choice, preserve server-side authorization, and verify each role after changing capabilities or moving administrative links.

Note: The date and certification information may change over time. It is advisable to verify the latest details on the plugin developer’s website.

Plugin Security Certification (PSC-2026-64688): “Admin Menu Editor” – Version 1.15.2

Dmitrii I

Pentester with 5 years of hands-on experience securing WordPress and web applications, holding OSWE, OSEP, OSCP, and OSWP certifications. Author of 450 published CVEs, including 35 disclosed within the last month. Specializes in discovering and validating high-impact vulnerabilities in WordPress plugins/themes / Custom WEB applications and delivering actionable remediation guidance to harden production sites.

Visit Author's Website

See all posts by dmitrii-ignatyev

Leave a Reply

Your email address will not be published. Required fields are marked *