
All Round Order Security & Risk Analysis
wordpress.org/plugins/all-round-orderOrder all items(Pages, Posts, Custom Post Types and attachments) easily with a drag and drop feature
Is All Round Order Safe to Use in 2026?
Generally Safe
Score 85/100All Round Order has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "all-round-order" plugin v1.1.0 exhibits a mixed security posture. On one hand, it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no known vulnerability history. This suggests a level of care in development regarding common web vulnerabilities.
However, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks. This creates a direct pathway for unauthenticated users to interact with potentially sensitive plugin functionalities. Furthermore, the taint analysis reveals flows with unsanitized paths, although no critical or high severity issues were identified. The complete absence of output escaping is a major red flag, as it leaves the plugin highly susceptible to Cross-Site Scripting (XSS) attacks through various input vectors.
While the plugin has no recorded CVEs, the identified weaknesses, particularly the unprotected AJAX endpoints and the lack of output escaping, present considerable risks. The absence of nonce checks on these AJAX handlers further exacerbates the potential for exploitation. Therefore, while the plugin has some strengths, the identified vulnerabilities require immediate attention to mitigate significant security risks.
Key Concerns
- AJAX handlers without authentication checks
- AJAX handlers without nonce checks
- Output escaping: 0% properly escaped
- Flows with unsanitized paths
All Round Order Security Vulnerabilities
All Round Order Code Analysis
Output Escaping
Data Flow Analysis
All Round Order Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
All Round Order Maintenance & Trust
Maintenance Signals
Community Trust
All Round Order Alternatives
Real Custom Post Order: Create a custom order for your content
real-custom-post-order
Custom post order for posts, pages, WooCommerce products and custom post types using drag and drop. Simple and intuitive sorting of your content!
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
Custom Category Post Order
custom-post-order-category
Order your post by category or custom post type by drag & drop interface.
My Post Order
my-posts-order
A plugin which allows you to sort posts, pages, custom post type in ANY order and display the same in your sidebar.
Sortable Posts
sortable-posts
Sortable Posts is a small plugin for WordPress that adds sortability to post types and taxonomies from the admin panel.
All Round Order Developer Profile
1 plugin · 40 total installs
How We Detect All Round Order
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-round-order/js/jquery-ui.min.js/wp-content/plugins/all-round-order/js/all-round-order.js/wp-content/plugins/all-round-order/css/all-round-order.css/wp-content/plugins/all-round-order/js/jquery-ui.min.js/wp-content/plugins/all-round-order/js/all-round-order.jsall-round-order/css/all-round-order.css?ver=all-round-order/js/jquery-ui.min.js?ver=all-round-order/js/all-round-order.js?ver=HTML / DOM Fingerprints
wbsoft-all-round-ordersortableplaceholder<!-- Javascript should be enabled to use this plugin. -->id="sortable"id="save-order"ajaxurljQueryupdate-custom-type-order