Archive Posts Sort Customize Security & Risk Analysis

wordpress.org/plugins/archive-posts-sort-customize

Customize the display order of the list of Archive Posts.

600 active installs v1.6.1 PHP + WP 4.3+ Updated Sep 24, 2015
archivecustomizefrontendpostssort
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Archive Posts Sort Customize Safe to Use in 2026?

Generally Safe

Score 85/100

Archive Posts Sort Customize has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "archive-posts-sort-customize" v1.6.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength. Furthermore, the complete lack of critical or high-severity taint flows, along with all SQL queries utilizing prepared statements, indicates robust practices in handling user input and database interactions. The presence of nonce and capability checks, although limited, also suggests an awareness of WordPress security best practices.

However, a notable concern arises from the output escaping. With 192 total outputs and only 64% properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means a substantial portion of the plugin's output is not being adequately sanitized, potentially allowing attackers to inject malicious scripts into pages rendered by the plugin. While the plugin has no recorded vulnerability history, this single weakness in output sanitization, if exploited, could lead to serious security breaches. The presence of one file operation without further context is also a minor point of attention, though its severity is unknown without deeper code review.

In conclusion, the plugin has a strong foundation with a minimal attack surface and secure data handling for SQL. The primary and most significant weakness is the insufficient output escaping, which demands immediate attention. The absence of past vulnerabilities is positive, but it should not overshadow the potential risks identified in the current static analysis. Addressing the output escaping issue is crucial to improving the overall security of this plugin.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Archive Posts Sort Customize Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Archive Posts Sort Customize Release Timeline

v1.6.1Current
v1.6
v1.5.1
v1.5
v1.4
v1.3.1
v1.2.4.2
v1.2.4.1
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2
v1.1.1
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Archive Posts Sort Customize Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
70
122 escaped
Nonce Checks
3
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

64% escaped192 total outputs
Attack Surface

Archive Posts Sort Customize Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionadmin_menuadmin\abstract-manager.php:79
actionadmin_noticesadmin\abstract-manager.php:90
actionadmin_enqueue_scriptsadmin\abstract-manager.php:150
actionadmin_initadmin\master.php:94
filterplugin_row_metaadmin\_setup.php:56
actionplugins_loadedarchive-posts-sort-customize.php:76
actionsetup_themearchive-posts-sort-customize.php:77
actionafter_setup_themearchive-posts-sort-customize.php:78
actioninitarchive-posts-sort-customize.php:79
actionwp_loadedarchive-posts-sort-customize.php:80
filterdebug_bar_panelsarchive-posts-sort-customize.php:183
actionwpfront\master.php:90
actionpre_get_postsfront\not-user-archives.php:28
filterposts_orderbyfront\not-user-archives.php:29
Maintenance & Trust

Archive Posts Sort Customize Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedSep 24, 2015
PHP min version
Downloads18K

Community Trust

Rating98/100
Number of ratings14
Active installs600
Developer Profile

Archive Posts Sort Customize Developer Profile

gqevu6bsiz

12 plugins · 47K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
183 days
View full developer profile
Detection Fingerprints

How We Detect Archive Posts Sort Customize

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/archive-posts-sort-customize/admin/assets/css/manager.css/wp-content/plugins/archive-posts-sort-customize/admin/assets/js/manager.js/wp-content/plugins/archive-posts-sort-customize/front/assets/css/front.css/wp-content/plugins/archive-posts-sort-customize/front/assets/js/front.js
Script Paths
/wp-content/plugins/archive-posts-sort-customize/admin/assets/js/manager.js/wp-content/plugins/archive-posts-sort-customize/front/assets/js/front.js
Version Parameters
archive-posts-sort-customize/admin/assets/css/manager.css?ver=archive-posts-sort-customize/admin/assets/js/manager.js?ver=archive-posts-sort-customize/front/assets/css/front.css?ver=archive-posts-sort-customize/front/assets/js/front.js?ver=

HTML / DOM Fingerprints

CSS Classes
apsc-archive-containerapsc-archive-postsapsc-archive-post-titleapsc-archive-post-metaapsc-archive-post-excerptapsc-archive-post-thumbnail
JS Globals
APSC
FAQ

Frequently Asked Questions about Archive Posts Sort Customize