AgentPress Listings Taxonomy Reorder Security & Risk Analysis

wordpress.org/plugins/agentpress-listings-taxonomy-reorder

Allows the reordering of AgentPress Listings taxonomies after creation.

80 active installs v1.0 PHP + WP 3.2+ Updated Jul 8, 2014
agentpressgenesisgenesiswp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AgentPress Listings Taxonomy Reorder Safe to Use in 2026?

Generally Safe

Score 85/100

AgentPress Listings Taxonomy Reorder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "agentpress-listings-taxonomy-reorder" plugin v1.0 exhibits a strong security posture based on the provided static analysis. The complete absence of identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) significantly reduces its attack surface. Furthermore, the code analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), and no file operations or external HTTP requests, all of which are excellent security practices. The lack of identified taint flows, critical or high severity issues, and the absence of any recorded vulnerabilities in its history further reinforce this positive assessment.

However, a significant concern arises from the output escaping signals. With 0% of the total outputs properly escaped, the plugin presents a risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users, if not properly sanitized before rendering, could be exploited by attackers. Additionally, the complete absence of nonce and capability checks on any potential, albeit currently unexposed, entry points indicates a potential oversight. While the attack surface is zero, if new entry points were introduced in future updates without implementing these checks, it could create immediate security holes.

In conclusion, while the plugin demonstrates robust security hygiene in several critical areas and has no historical vulnerabilities, the lack of output escaping is a notable weakness that needs immediate attention to mitigate XSS risks. The absence of nonce and capability checks, while not currently exploitable due to the limited attack surface, represents a potential future vulnerability if the plugin evolves without addressing this.

Key Concerns

  • Output escaping is not implemented
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

AgentPress Listings Taxonomy Reorder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AgentPress Listings Taxonomy Reorder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

AgentPress Listings Taxonomy Reorder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuap-tax-reorder.php:11
actionadmin_enqueue_scriptsap-tax-reorder.php:16
Maintenance & Trust

AgentPress Listings Taxonomy Reorder Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJul 8, 2014
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs80
Developer Profile

AgentPress Listings Taxonomy Reorder Developer Profile

unclhos

3 plugins · 880 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AgentPress Listings Taxonomy Reorder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/agentpress-listings-taxonomy-reorder/ap-tax-reorder.php

HTML / DOM Fingerprints

CSS Classes
ap-submitap-tax-reorder
Data Attributes
id="ap-tax[]"name="ap-tax[]"
JS Globals
jQuery
FAQ

Frequently Asked Questions about AgentPress Listings Taxonomy Reorder