
Custom Post Order Security & Risk Analysis
wordpress.org/plugins/custom-post-orderdescending , posts, categories, wordpress mu, wpmu Requires at least: 2.6 Tested up to: 2.7 Stable tag: trunk The plugin enables any user to modify t …
Is Custom Post Order Safe to Use in 2026?
Generally Safe
Score 85/100Custom Post Order has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'custom-post-order' plugin version 1.1 presents a generally positive security posture based on the static analysis. It demonstrates good practices by having zero AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points. The absence of dangerous functions and file operations further strengthens its security. Crucially, all SQL queries utilize prepared statements, and there are no recorded vulnerabilities, suggesting a history of responsible development and maintenance.
However, a significant concern arises from the output escaping. With two total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from or passes through this plugin without proper sanitization could be exploited by attackers to inject malicious scripts. While the taint analysis shows no flows, this is likely due to the limited or non-existent entry points that would typically trigger such analysis. The presence of a nonce check and capability check is positive but doesn't mitigate the XSS risk if the output itself is not escaped.
In conclusion, while the plugin excels in preventing direct unauthorized access and injection vectors through its limited attack surface and secure database interactions, the lack of output escaping is a critical weakness. This single oversight creates a significant XSS vulnerability that could be exploited. The plugin's history of zero vulnerabilities is a positive indicator, but it doesn't negate the present risk of unescaped output.
Key Concerns
- 0% output escaping
Custom Post Order Security Vulnerabilities
Custom Post Order Code Analysis
Output Escaping
Custom Post Order Attack Surface
WordPress Hooks 2
Maintenance & Trust
Custom Post Order Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post Order Alternatives
Posts by Taxonomy
posts-by-taxonomy
Display a list separated by any taxonomy via shortcode.
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
Simple Custom Post Order
simple-custom-post-order
Easily reorder posts, pages, custom post types, and taxonomies with intuitive drag-and-drop sorting in the WordPress admin.
Real Custom Post Order: Create a custom order for your content
real-custom-post-order
Custom post order for posts, pages, WooCommerce products and custom post types using drag and drop. Simple and intuitive sorting of your content!
ReOrder Posts within Categories
reorder-post-within-categories
Enables manual ranking of post (and custom post) within taxonomy terms using a drag & drop grid interface.
Custom Post Order Developer Profile
15 plugins · 6K total installs
How We Detect Custom Post Order
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
License: GPLCustom Post Order - brief descriptionCopyright (C) 2008, OLT, http://olt.ubc.caThis program is free software; you can redistribute it and/or+17 moredirname