
Custom Reorder Manager Security & Risk Analysis
wordpress.org/plugins/custom-reorder-managerReorder WordPress posts with drag & drop mechanism.
Is Custom Reorder Manager Safe to Use in 2026?
Generally Safe
Score 85/100Custom Reorder Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-reorder-manager" v1.2.0 plugin exhibits a concerning security posture due to several critical weaknesses, despite a clean vulnerability history and the absence of dangerous functions or unsanitized taint flows. The primary concern is the presence of an unprotected AJAX handler, which represents a direct entry point into the application that lacks any authentication or capability checks. This is further exacerbated by the complete lack of output escaping for all identified outputs, meaning any data processed or displayed through the plugin is vulnerable to cross-site scripting (XSS) attacks. While the plugin utilizes prepared statements for its SQL queries, this single positive aspect is overshadowed by the significant risks posed by the unprotected AJAX handler and the pervasive unescaped output. The lack of any recorded vulnerabilities in its history might suggest it hasn't been a target, or perhaps that prior versions were less exposed. However, the current version's identifiable vulnerabilities, particularly the unprotected AJAX endpoint and unescaped output, demand immediate attention.
Key Concerns
- Unprotected AJAX handler
- All outputs unescaped
- No nonce checks on AJAX
- No capability checks on AJAX
Custom Reorder Manager Security Vulnerabilities
Custom Reorder Manager Code Analysis
SQL Query Safety
Output Escaping
Custom Reorder Manager Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
Custom Reorder Manager Maintenance & Trust
Maintenance Signals
Community Trust
Custom Reorder Manager Alternatives
Simple Custom Post Order
simple-custom-post-order
Easily reorder posts, pages, custom post types, and taxonomies with intuitive drag-and-drop sorting in the WordPress admin.
Reorder Posts
metronet-reorder-posts
A simple and easy way to reorder your custom post types in WordPress.
Custom Category Post Order
custom-post-order-category
Order your post by category or custom post type by drag & drop interface.
GAP3 Coders Taxonomy Post Order
gap3coders-taxonomy-post-order
Easily reorder posts within taxonomy terms using drag-and-drop interface. Custom order automatically applies to frontend without any code changes.
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
Custom Reorder Manager Developer Profile
1 plugin · 10 total installs
How We Detect Custom Reorder Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-reorder-manager/assets/js/cro.js/wp-content/plugins/custom-reorder-manager/assets/js/sortable.js/wp-content/plugins/custom-reorder-manager/assets/css/cro.css/wp-content/plugins/custom-reorder-manager/assets/js/cro.js/wp-content/plugins/custom-reorder-manager/assets/js/sortable.jscustom-reorder-manager/assets/js/cro.js?ver=custom-reorder-manager/assets/js/sortable.js?ver=HTML / DOM Fingerprints
cro-wrapper-containercro-wrappercro-settingscro-setting-headercro