
Custom Category Post Order Security & Risk Analysis
wordpress.org/plugins/custom-post-order-categoryOrder your post by category or custom post type by drag & drop interface.
Is Custom Category Post Order Safe to Use in 2026?
Generally Safe
Score 99/100Custom Category Post Order has a strong security track record. Known vulnerabilities have been patched promptly.
The "custom-post-order-category" v2.2 plugin exhibits a generally strong security posture, with several key strengths. The static analysis reveals a commendable use of prepared statements for SQL queries (92%) and proper output escaping (86%). Importantly, all identified entry points, including AJAX handlers, are protected with nonce and capability checks, and there are no critical or high severity taint flows found. The absence of file operations and external HTTP requests further reduces the attack surface. The plugin also demonstrates a proactive approach to security by not bundling external libraries, which can become outdated and vulnerable.
However, a past medium severity vulnerability related to missing authorization, though now patched, warrants attention. This indicates a historical pattern that, while addressed, suggests a need for continued vigilance. The presence of 6 AJAX handlers, while secured, still represents a potential attack surface that attackers might probe for subtle logic flaws or timing issues. Although no current critical issues are evident, the historical medium vulnerability is a significant indicator that authorization checks, even if present, might require thorough auditing in future versions.
In conclusion, v2.2 of "custom-post-order-category" appears to be a relatively secure plugin with good coding practices in place. The historical vulnerability is a reminder of the importance of ongoing security audits, but the current code analysis is largely reassuring. The plugin's strengths lie in its adherence to secure coding principles for database interaction and output handling, and its complete protection of entry points.
Key Concerns
- Past medium severity vulnerability
Custom Category Post Order Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Custom Category/Post Type Post order <= 1.6.0 - Missing Authorization
Custom Category Post Order Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Custom Category Post Order Attack Surface
AJAX Handlers 6
WordPress Hooks 11
Maintenance & Trust
Custom Category Post Order Maintenance & Trust
Maintenance Signals
Community Trust
Custom Category Post Order Alternatives
Simple Custom Post Order
simple-custom-post-order
Easily reorder posts, pages, custom post types, and taxonomies with intuitive drag-and-drop sorting in the WordPress admin.
Real Custom Post Order: Create a custom order for your content
real-custom-post-order
Custom post order for posts, pages, WooCommerce products and custom post types using drag and drop. Simple and intuitive sorting of your content!
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
Reorder Posts
metronet-reorder-posts
A simple and easy way to reorder your custom post types in WordPress.
Posts Order
category-custom-post-order
Order posts separately for each terms and taxonomies
Custom Category Post Order Developer Profile
6 plugins · 630 total installs
How We Detect Custom Category Post Order
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-post-order-category/css/admin-style.css/wp-content/plugins/custom-post-order-category/js/admin-script.js/wp-content/plugins/custom-post-order-category/js/jquery-ui.min.js/wp-content/plugins/custom-post-order-category/js/admin-script.js/wp-content/plugins/custom-post-order-category/js/jquery-ui.min.jsHTML / DOM Fingerprints
drag_postsortablesortableulpost_titleccpo_get_terms