
Anything Order by Terms Security & Risk Analysis
wordpress.org/plugins/anything-order-by-termsThis plugin allows you to arrange any post types and terms with drag and drop. Save post order for each term.
Is Anything Order by Terms Safe to Use in 2026?
Use With Caution
Score 63/100Anything Order by Terms has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "anything-order-by-terms" v1.4.0 plugin exhibits a mixed security posture. While static analysis indicates a minimal attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events without authentication or permission checks, and no critical taint analysis findings, there are significant concerns.
The presence of a single SQL query that is not using prepared statements is a notable weakness, potentially exposing the site to SQL injection vulnerabilities. Furthermore, the output escaping is not consistently applied, with 43% of outputs not being properly escaped, creating an XSS risk. The vulnerability history reveals a concerning pattern, with a medium-severity vulnerability reported and still unpatched. The common vulnerability type being "Missing Authorization" is also a red flag, especially given the plugin's limited disclosed entry points.
Overall, while the plugin appears to have a small attack surface and some good practices like nonce and capability checks, the unpatched medium vulnerability, the raw SQL query, and the insufficient output escaping present clear and actionable risks that need to be addressed.
Key Concerns
- Unpatched medium vulnerability
- Raw SQL query without prepared statements
- Insufficient output escaping (43% not properly escaped)
Anything Order by Terms Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Anything Order by Terms <= 1.4.0 - Missing Authorization
Anything Order by Terms Release Timeline
Anything Order by Terms Code Analysis
SQL Query Safety
Output Escaping
Anything Order by Terms Attack Surface
WordPress Hooks 11
Maintenance & Trust
Anything Order by Terms Maintenance & Trust
Maintenance Signals
Community Trust
Anything Order by Terms Alternatives
Anything Order
anything-order
Reorder any post types and taxonomies with drag and drop.
Post Order Manager
post-order-manager
Reorder posts using a simple drag-and-drop interface and update the menu_order field in seconds.
Admin Menu Customizer
admin-menu-customizer
Customize the order of the admin menu and optionally change menu item titles or hide some items.
AJAX Admin Menu Editor
ajax-admin-menu-editor
Easily reorder your admin menu items with simple drag & drop operation
Product Customer List for WooCommerce
wc-product-customer-list
Display a list of customers who bought a specific product at the bottom of the product edit page in WooCommerce and send them e-mails.
Anything Order by Terms Developer Profile
2 plugins · 1K total installs
How We Detect Anything Order by Terms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/anything-order-by-terms/assets/css/admin.css/wp-content/plugins/anything-order-by-terms/assets/css/style.css/wp-content/plugins/anything-order-by-terms/assets/js/admin.js/wp-content/plugins/anything-order-by-terms/assets/js/admin_order.js/wp-content/plugins/anything-order-by-terms/assets/js/libs/jquery/ui.min.js/wp-content/plugins/anything-order-by-terms/assets/js/admin.js/wp-content/plugins/anything-order-by-terms/assets/js/admin_order.js/wp-content/plugins/anything-order-by-terms/assets/js/libs/jquery/ui.min.jsanything-order-by-terms/assets/css/admin.css?ver=anything-order-by-terms/assets/css/style.css?ver=anything-order-by-terms/assets/js/admin.js?ver=anything-order-by-terms/assets/js/admin_order.js?ver=anything-order-by-terms/assets/js/libs/jquery/ui.min.js?ver=HTML / DOM Fingerprints
anything-orderanything-order-idanything-order-orderdata-actiondata-iddata-orderAnything_Orderanything_order_i18n/wp-json/anything-order/v1/update