
Archive Post Order Plus Security & Risk Analysis
wordpress.org/plugins/archive-post-order-plusA plugin that sets the display order of posts. 投稿の表示順を設定するプラグイン。
Is Archive Post Order Plus Safe to Use in 2026?
Generally Safe
Score 100/100Archive Post Order Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'archive-post-order-plus' plugin v1.2.4 demonstrates a generally strong security posture, with no known vulnerabilities in its history and robust handling of SQL queries and output escaping. The code analysis reveals a minimal attack surface, with only one entry point identified as an AJAX handler. However, this single AJAX handler lacks authentication checks, which represents a significant security concern. The absence of capability checks on this entry point further exacerbates this risk, as it could potentially be exploited by any unauthenticated user to perform unintended actions. While the plugin's adherence to prepared statements and a high percentage of properly escaped outputs are commendable, the unprotected AJAX handler is a critical weakness that needs immediate attention. The lack of any recorded vulnerabilities in its history is a positive indicator, suggesting a commitment to security by the developers, but this should not overshadow the identified risk in the current version.
Key Concerns
- AJAX handler without authentication
- AJAX handler without capability checks
Archive Post Order Plus Security Vulnerabilities
Archive Post Order Plus Release Timeline
Archive Post Order Plus Code Analysis
SQL Query Safety
Output Escaping
Archive Post Order Plus Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Archive Post Order Plus Maintenance & Trust
Maintenance Signals
Community Trust
Archive Post Order Plus Alternatives
No alternatives data available yet.
Archive Post Order Plus Developer Profile
3 plugins · 70 total installs
How We Detect Archive Post Order Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/archive-post-order-plus/css/jquery-ui.css/wp-content/plugins/archive-post-order-plus/css/apop-style.css/wp-content/plugins/archive-post-order-plus/js/apop-style.js/wp-content/plugins/archive-post-order-plus/js/custom_field.js/wp-content/plugins/archive-post-order-plus/js/apop-style.js/wp-content/plugins/archive-post-order-plus/js/custom_field.jsarchive-post-order-plus/css/jquery-ui.css?ver=archive-post-order-plus/css/apop-style.css?ver=archive-post-order-plus/js/apop-style.js?ver=archive-post-order-plus/js/custom_field.js?ver=HTML / DOM Fingerprints
data-apop-customfield-selectAPOP