Blog Posts Order Security & Risk Analysis

wordpress.org/plugins/blog-posts-order

This plugin lets you order the posts on the blog by manuallyl specified order.

90 active installs v1.0 PHP + WP 3.0.1+ Updated Dec 13, 2012
blogcustom-orderposts-orderposts-ordering
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Blog Posts Order Safe to Use in 2026?

Generally Safe

Score 85/100

Blog Posts Order has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "blog-posts-order" v1.0 plugin exhibits a remarkably clean static analysis profile, indicating strong adherence to secure coding practices. The absence of any identified dangerous functions, file operations, or external HTTP requests is commendable. Crucially, all SQL queries are prepared, and all outputs are properly escaped, which significantly mitigates common web application vulnerabilities like SQL injection and cross-site scripting. The attack surface is zero, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, suggesting a minimal footprint and limited opportunities for direct exploitation.

Furthermore, the plugin's vulnerability history is entirely clear, with no recorded CVEs. This lack of past security incidents, coupled with the current clean code analysis, suggests a well-maintained and secure plugin. The absence of taint analysis findings further reinforces the impression of robust security. However, the complete absence of capability checks and nonce checks, while not a direct vulnerability in this version given the zero attack surface, could represent a potential weakness if new entry points are introduced in future versions without corresponding security measures. In conclusion, this plugin appears to be highly secure based on the provided data, with a strong emphasis on preventing common vulnerabilities.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Blog Posts Order Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Blog Posts Order Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Blog Posts Order Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionpre_get_postsblogpostsorder.php:19
Maintenance & Trust

Blog Posts Order Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedDec 13, 2012
PHP min version
Downloads7K

Community Trust

Rating60/100
Number of ratings3
Active installs90
Developer Profile

Blog Posts Order Developer Profile

Gagan Goraya

3 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Blog Posts Order

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/blog-posts-order/blogpostsorder.php
Version Parameters
blog-posts-order/blogpostsorder.php?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Blog Posts Order