Anything Order Security & Risk Analysis

wordpress.org/plugins/anything-order

Reorder any post types and taxonomies with drag and drop.

300 active installs v1.0.3 PHP + WP 3.8+ Updated May 9, 2014
admincustomdrag-and-dropmenu_orderorder
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Anything Order Safe to Use in 2026?

Generally Safe

Score 85/100

Anything Order has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "anything-order" v1.0.3 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any attack surface, dangerous functions, file operations, or external HTTP requests is highly commendable. Furthermore, the presence of nonce and capability checks, along with a reasonable percentage of SQL queries using prepared statements, indicates a developer who is aware of and implementing some fundamental security practices. The lack of any recorded vulnerabilities in its history further reinforces this positive assessment.

However, a significant concern arises from the output escaping analysis. With only 57% of outputs properly escaped, there is a notable risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied data, if not handled carefully within the plugin's rendering logic, could be injected and executed in the browser of other users. While the taint analysis shows no identified flows with unsanitized paths, this could be due to the limited scope of the analysis or the absence of specific triggerable input vectors that the analysis tool identified. The overall score starts strong, but the output escaping issue introduces a tangible risk that needs attention.

In conclusion, the "anything-order" plugin is well-structured and avoids many common pitfalls. Its clean attack surface and lack of historical vulnerabilities are significant strengths. The primary area for improvement and the main security concern is the insufficient output escaping, which could lead to XSS vulnerabilities if not addressed. If this issue is resolved, the plugin would represent a very secure addition to a WordPress site.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Anything Order Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Anything Order Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
7 prepared
Unescaped Output
3
4 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

70% prepared10 total queries

Output Escaping

57% escaped7 total outputs
Attack Surface

Anything Order Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionplugins_loadedanything-order.php:68
actionadmin_initmodules\base\class.php:93
actioncurrent_screenmodules\base\class.php:94
filterposts_orderbymodules\post\class.php:25
actioncreate_termmodules\taxonomy\class.php:25
actiondelete_term_taxonomymodules\taxonomy\class.php:26
filterget_termmodules\taxonomy\class.php:27
filterterms_clausesmodules\taxonomy\class.php:28
filterget_the_termsmodules\taxonomy\class.php:29
filterwp_get_object_termsmodules\taxonomy\class.php:30
Maintenance & Trust

Anything Order Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedMay 9, 2014
PHP min version
Downloads10K

Community Trust

Rating98/100
Number of ratings12
Active installs300
Developer Profile

Anything Order Developer Profile

Pimp My Site

1 plugin · 300 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Anything Order

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/anything-order/modules/base/style.css/wp-content/plugins/anything-order/modules/base/script.js
Script Paths
/wp-content/plugins/anything-order/modules/base/script.js

HTML / DOM Fingerprints

CSS Classes
anything-order-actionsanything-order-idanything-order-order
Data Attributes
data-anything-order
JS Globals
anythingOrder
REST Endpoints
/wp-json/anything-order/update/taxonomy/wp-json/anything-order/update/post
FAQ

Frequently Asked Questions about Anything Order