If I were to disable the log-in for the script will it be secure wrapped up in the MODx core folders?
Probably not. If building a component from scratch it builds up dependencies to MODX, so wont run without it (ie direct access). What you could do is do something like this in the script instead of its login:
if (!$modx || !($modx instanceof modX)) { die('No direct access allowed'); }
if (!$modx->user || !$modx->user->hasSessionContext('mgr')) { die ('Please make sure you are logged in to the MODX Manager'); }
I have Revolution 2.2.0-pl2 and when I right click the Components there is a mandatory field called: "Lexicon Key" what would I enter here?
Looks like you figured it out, but that's where you enter the menu items' name. You can use lexicons there, which are translated strings basically, which explains the name. If you're just doing a simple integration you likely don't have the lexicon files in place though.
I created a test page and it shows in the menu and displays. I do have one problem though, the page shows above everything else including the menu, instead of showing below the menu like the other pages. Any idea as to how I can fix this?
One out of two things:
1. Modify the script to not use "echo" or "print", but to return all content output at the end of the processing with the "return" statement.
2. Create a new file that you set up as the action controller, which return's an iframe to your custom script. With this you will lose access to $modx though, so the security checks above wouldn't work anymore.