Archive Post Order Plus Security & Risk Analysis

wordpress.org/plugins/archive-post-order-plus

A plugin that sets the display order of posts. 投稿の表示順を設定するプラグイン。

10 active installs v1.2.4 PHP 8.2+ WP 6.7+ Updated Dec 18, 2025
categories-post-ordercustom-taxonomy-post-orderlatest-posts-ordertags-post-order
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Archive Post Order Plus Safe to Use in 2026?

Generally Safe

Score 100/100

Archive Post Order Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The 'archive-post-order-plus' plugin v1.2.4 demonstrates a generally strong security posture, with no known vulnerabilities in its history and robust handling of SQL queries and output escaping. The code analysis reveals a minimal attack surface, with only one entry point identified as an AJAX handler. However, this single AJAX handler lacks authentication checks, which represents a significant security concern. The absence of capability checks on this entry point further exacerbates this risk, as it could potentially be exploited by any unauthenticated user to perform unintended actions. While the plugin's adherence to prepared statements and a high percentage of properly escaped outputs are commendable, the unprotected AJAX handler is a critical weakness that needs immediate attention. The lack of any recorded vulnerabilities in its history is a positive indicator, suggesting a commitment to security by the developers, but this should not overshadow the identified risk in the current version.

Key Concerns

  • AJAX handler without authentication
  • AJAX handler without capability checks
Vulnerabilities
None known

Archive Post Order Plus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Archive Post Order Plus Release Timeline

v1.2.4Current
Code Analysis
Analyzed Apr 16, 2026

Archive Post Order Plus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
6
160 escaped
Nonce Checks
15
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

96% escaped166 total outputs
Attack Surface
1 unprotected

Archive Post Order Plus Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_set_custom_fieldclass/class.apop.order.php:23
WordPress Hooks 6
actionadmin_enqueue_scriptsarchive-post-order-plus.php:42
actionadmin_menuclass/class.apop.apop_post.php:25
actionsave_postclass/class.apop.apop_post.php:26
actionadmin_menuclass/class.apop.order.php:21
actionadmin_enqueue_scriptsclass/class.apop.order.php:22
actionpre_get_postsutil/apop-order-setting.php:12
Maintenance & Trust

Archive Post Order Plus Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 18, 2025
PHP min version8.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Archive Post Order Plus Alternatives

No alternatives data available yet.

Developer Profile

Archive Post Order Plus Developer Profile

NBK45

3 plugins · 70 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Archive Post Order Plus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/archive-post-order-plus/css/jquery-ui.css/wp-content/plugins/archive-post-order-plus/css/apop-style.css/wp-content/plugins/archive-post-order-plus/js/apop-style.js/wp-content/plugins/archive-post-order-plus/js/custom_field.js
Script Paths
/wp-content/plugins/archive-post-order-plus/js/apop-style.js/wp-content/plugins/archive-post-order-plus/js/custom_field.js
Version Parameters
archive-post-order-plus/css/jquery-ui.css?ver=archive-post-order-plus/css/apop-style.css?ver=archive-post-order-plus/js/apop-style.js?ver=archive-post-order-plus/js/custom_field.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-apop-customfield-select
JS Globals
APOP
FAQ

Frequently Asked Questions about Archive Post Order Plus