CMB Field Type: Sorter Security & Risk Analysis

wordpress.org/plugins/cmb-field-type-sorter

This plugin gives you two CMB field types based on the Sorter script:

10 active installs v1.0.0 PHP + WP 3.6.1+ Updated May 20, 2015
jqueryuilayoutsorter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CMB Field Type: Sorter Safe to Use in 2026?

Generally Safe

Score 85/100

CMB Field Type: Sorter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin "cmb-field-type-sorter" v1.0.0 exhibits a seemingly secure static analysis profile with no identified dangerous functions, SQL injection vulnerabilities, or external HTTP requests. The absence of known CVEs and a clean vulnerability history is also a positive indicator. However, a significant concern arises from the 0% output escaping. This means that any data processed and displayed by the plugin, even if it appears to be benign, could potentially contain malicious code that would be executed by the user's browser, leading to cross-site scripting (XSS) vulnerabilities. While the attack surface appears minimal (0 entry points), the lack of output escaping is a critical oversight that exposes users to significant risk.

The plugin's reported lack of nonce checks and capability checks, coupled with the zero entry points, suggests it might not handle any user-interactive data that requires such security measures. However, if the plugin's functionality evolves or if there are hidden or unexpected ways it handles data, the absence of these checks could become a vulnerability. The current data presents a paradox: a clean history and analysis in most areas, but a glaring weakness in output escaping that undermines the otherwise positive findings.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

CMB Field Type: Sorter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

CMB Field Type: Sorter Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

CMB Field Type: Sorter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

CMB Field Type: Sorter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtercmb2_render_tb_sortercmb-field-sorter.php:66
filtercmb2_types_esc_tb_sortercmb-field-sorter.php:77
filtercmb2_sanitize_tb_sortercmb-field-sorter.php:87
Maintenance & Trust

CMB Field Type: Sorter Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedMay 20, 2015
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

CMB Field Type: Sorter Developer Profile

Tran Bang

2 plugins · 510 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CMB Field Type: Sorter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cmb-field-type-sorter/css/sorter.css/wp-content/plugins/cmb-field-type-sorter/js/sorter-init.js
Script Paths
/wp-content/plugins/cmb-field-type-sorter/js/sorter-init.js
Version Parameters
cmb-field-type-sorter/style.css?ver=cmb-field-type-sorter/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
tb-field-containertb-sorter-containertb-sortersortlist_sortee
Data Attributes
data-iddata-group-id
FAQ

Frequently Asked Questions about CMB Field Type: Sorter