
Category Commander Security & Risk Analysis
wordpress.org/plugins/category-commanderDrag & drop ordering for Categories with secure saving, optional autosort, JSON export/import, and accessibility enhancements.
Is Category Commander Safe to Use in 2026?
Generally Safe
Score 100/100Category Commander has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "category-commander" plugin v1.0.5 presents a generally strong security posture based on the static analysis and vulnerability history. The plugin demonstrates good security practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks on several of its entry points. The complete absence of any recorded vulnerabilities, including critical or high severity ones, and a lack of dangerous functions or file operations further contribute to a positive security assessment.
However, a notable concern arises from the output escaping analysis. While a majority of outputs are properly escaped, a significant portion (37%) are not. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly echoed without adequate sanitization. The lack of taint analysis results, while potentially meaning no critical flows were found, also means we cannot definitively rule out all forms of taint-related issues. Despite this, the overall picture is one of a well-maintained and relatively secure plugin, with the primary area for improvement being the consistent application of output escaping.
Key Concerns
- Significant percentage of unescaped output
Category Commander Security Vulnerabilities
Category Commander Code Analysis
SQL Query Safety
Output Escaping
Category Commander Attack Surface
REST API Routes 4
WordPress Hooks 12
Maintenance & Trust
Category Commander Maintenance & Trust
Maintenance Signals
Community Trust
Category Commander Alternatives
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
WP Category Sort
wp-category-sort
The WP Category Sort plugin allows you to easily reorder your categories the way you want via drag and drop.
Custom Taxonomy Order
custom-taxonomy-order-ne
Allows for the ordering of categories and custom taxonomy terms through a simple drag-and-drop interface
Categories in Hierarchical Order
categories-in-hierarchical-order
Categories in Hierarchical Order plugin maintains the hierarchical order of categories list in the Category tab under your WordPress Admin Post Editor …
Posts Order
category-custom-post-order
Order posts separately for each terms and taxonomies
Category Commander Developer Profile
1 plugin · 20 total installs
How We Detect Category Commander
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/category-commander/assets/admin.css/wp-content/plugins/category-commander/assets/admin.jscategory-commander/assets/admin.css?ver=category-commander/assets/admin.js?ver=HTML / DOM Fingerprints
category-commander-wrap<!-- IMPORTANT: The `get_terms` ORDERBY is set to `cateco_order` by this plugin. --><!-- You can reset the custom order on the Category Commander settings page. --><!-- Tip: Click a category (or Tab to its handle), then use Alt (Option on Mac) + ↑ / ↓ to move it with the keyboard. --><!-- Note: If you use caching (plugin, CDN, or server cache), consider clearing it before retesting. -->+2 moredata-action="cateco_save_settings"data-confirm="resetConfirm"data-nonce="cateco_save_settings"data-autosort-frontdata-autosort-admindata-save-url+1 moreCatecoAdmin/category-commander/v1/categories