
Boone's Sortable Columns Security & Risk Analysis
wordpress.org/plugins/boones-sortable-columnsA handy, extensible class for adding sortable columns your custom post type lists.
Is Boone's Sortable Columns Safe to Use in 2026?
Generally Safe
Score 100/100Boone's Sortable Columns has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "boones-sortable-columns" plugin v1.1 exhibits a generally strong security posture based on the provided static analysis. It demonstrates a complete absence of known vulnerabilities in its history, suggesting a history of responsible development and patching. Furthermore, the code analysis reveals no dangerous functions, no raw SQL queries (all use prepared statements), no file operations, and no external HTTP requests, which are all positive indicators. The lack of shortcodes, cron events, and particularly unprotected AJAX handlers or REST API routes significantly minimizes the potential attack surface.
However, a significant concern arises from the complete lack of output escaping. With four identified output points and 0% properly escaped, this presents a direct risk of cross-site scripting (XSS) vulnerabilities. If any data processed by this plugin is rendered directly in the browser without proper sanitization, an attacker could inject malicious scripts. Additionally, the complete absence of nonce and capability checks on any entry points (though the entry points are zero) is a weakness, as it implies a lack of robust access control mechanisms, even if currently not exploitable due to the limited attack surface. The absence of taint analysis data is also notable, as it prevents a deeper understanding of data flow risks.
In conclusion, while the plugin benefits from a clean vulnerability history and a small, seemingly secure attack surface with regards to SQL injection and other common web vulnerabilities, the unescaped output is a critical flaw that cannot be overlooked. The lack of any recorded vulnerabilities could also be partly due to the plugin's limited functionality or a lack of in-depth security auditing rather than inherent security. The strength lies in its lack of common vulnerabilities, but the weakness in output handling requires immediate attention.
Key Concerns
- 0% output escaping
- No capability checks
- No nonce checks
Boone's Sortable Columns Security Vulnerabilities
Boone's Sortable Columns Code Analysis
Output Escaping
Boone's Sortable Columns Attack Surface
Maintenance & Trust
Boone's Sortable Columns Maintenance & Trust
Maintenance Signals
Community Trust
Boone's Sortable Columns Alternatives
Admin Columns
codepress-admin-columns
Customise columns on the administration screens for post(types), pages, media, comments, links and users with an easy to use drag-and-drop interface.
Post Admin Word Count
post-admin-word-count
Adds a sortable word count column to the admin post list for all public post types. Efficient, lightweight and built with modern best practices.
Mimo Masonry
mimo-masonry
Creates a Widget to display a Masonry, Infinite scroll, filterable loop of posts or whatever custom post type you have. Includes 1-20 columns layout.
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
TablePress – Tables in WordPress made easy
tablepress
Embed beautiful, accessible, and interactive tables into your WordPress website’s posts and pages, without having to write code!
Boone's Sortable Columns Developer Profile
27 plugins · 12K total installs
How We Detect Boone's Sortable Columns
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/boones-sortable-columns/boones-sortable-columns.js/wp-content/plugins/boones-sortable-columns/boones-sortable-columns.jsboones-sortable-columns/boones-sortable-columns.js?ver=HTML / DOM Fingerprints
sortableascdescdata-bbg-cpt-sortbbg_cpt_sort