
Anything Order Security & Risk Analysis
wordpress.org/plugins/anything-orderReorder any post types and taxonomies with drag and drop.
Is Anything Order Safe to Use in 2026?
Generally Safe
Score 85/100Anything Order has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "anything-order" v1.0.3 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any attack surface, dangerous functions, file operations, or external HTTP requests is highly commendable. Furthermore, the presence of nonce and capability checks, along with a reasonable percentage of SQL queries using prepared statements, indicates a developer who is aware of and implementing some fundamental security practices. The lack of any recorded vulnerabilities in its history further reinforces this positive assessment.
However, a significant concern arises from the output escaping analysis. With only 57% of outputs properly escaped, there is a notable risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied data, if not handled carefully within the plugin's rendering logic, could be injected and executed in the browser of other users. While the taint analysis shows no identified flows with unsanitized paths, this could be due to the limited scope of the analysis or the absence of specific triggerable input vectors that the analysis tool identified. The overall score starts strong, but the output escaping issue introduces a tangible risk that needs attention.
In conclusion, the "anything-order" plugin is well-structured and avoids many common pitfalls. Its clean attack surface and lack of historical vulnerabilities are significant strengths. The primary area for improvement and the main security concern is the insufficient output escaping, which could lead to XSS vulnerabilities if not addressed. If this issue is resolved, the plugin would represent a very secure addition to a WordPress site.
Key Concerns
- Unescaped output detected
Anything Order Security Vulnerabilities
Anything Order Code Analysis
SQL Query Safety
Output Escaping
Anything Order Attack Surface
WordPress Hooks 10
Maintenance & Trust
Anything Order Maintenance & Trust
Maintenance Signals
Community Trust
Anything Order Alternatives
Anything Order by Terms
anything-order-by-terms
This plugin allows you to arrange any post types and terms with drag and drop. Save post order for each term.
Post Order Manager
post-order-manager
Reorder posts using a simple drag-and-drop interface and update the menu_order field in seconds.
Admin Menu Customizer
admin-menu-customizer
Customize the order of the admin menu and optionally change menu item titles or hide some items.
AJAX Admin Menu Editor
ajax-admin-menu-editor
Easily reorder your admin menu items with simple drag & drop operation
Product Customer List for WooCommerce
wc-product-customer-list
Display a list of customers who bought a specific product at the bottom of the product edit page in WooCommerce and send them e-mails.
Anything Order Developer Profile
1 plugin · 300 total installs
How We Detect Anything Order
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/anything-order/modules/base/style.css/wp-content/plugins/anything-order/modules/base/script.js/wp-content/plugins/anything-order/modules/base/script.jsHTML / DOM Fingerprints
anything-order-actionsanything-order-idanything-order-orderdata-anything-orderanythingOrder/wp-json/anything-order/update/taxonomy/wp-json/anything-order/update/post