
Custom Taxonomy Sort Security & Risk Analysis
wordpress.org/plugins/custom-taxonomy-sortCustom Taxonomy Sort allows you to explicitly control the sort order of all taxonomy terms.
Is Custom Taxonomy Sort Safe to Use in 2026?
Generally Safe
Score 85/100Custom Taxonomy Sort has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-taxonomy-sort" v1.1.5 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any detected critical or high-severity taint flows, dangerous functions, file operations, or external HTTP requests is a significant strength. Furthermore, the plugin boasts zero known CVEs, indicating a history of stable and secure development. The plugin also has a very small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without proper authentication or permission checks.
However, there are areas for improvement. The low percentage of properly escaped output (13%) is a notable concern, as it suggests a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed. While no specific XSS vulnerabilities were detected in the taint analysis (likely due to the limited scope or nature of the analyzed flows), the underlying pattern of insufficient output escaping is a common precursor to such attacks. The fact that 25% of SQL queries are not using prepared statements also presents a potential risk of SQL injection, although the analysis did not identify specific exploitable flows.
In conclusion, the plugin has a generally good security foundation with no critical vulnerabilities reported and a well-defined, secure attack surface. The primary weaknesses lie in the potential for XSS due to inadequate output escaping and the risk of SQL injection from non-prepared SQL queries. Addressing these specific code-level concerns would further solidify the plugin's security.
Key Concerns
- Low percentage of properly escaped output
- SQL queries not using prepared statements
Custom Taxonomy Sort Security Vulnerabilities
Custom Taxonomy Sort Code Analysis
SQL Query Safety
Output Escaping
Custom Taxonomy Sort Attack Surface
WordPress Hooks 11
Maintenance & Trust
Custom Taxonomy Sort Maintenance & Trust
Maintenance Signals
Community Trust
Custom Taxonomy Sort Alternatives
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
WP Category Sort
wp-category-sort
The WP Category Sort plugin allows you to easily reorder your categories the way you want via drag and drop.
Category Commander
category-commander
Drag & drop ordering for Categories with secure saving, optional autosort, JSON export/import, and accessibility enhancements.
Categories Images
categories-images
The Categories Images is a Wordpress plugin allow you to add image to category, tag or custom taxonomy.
Custom Taxonomy Order
custom-taxonomy-order-ne
Allows for the ordering of categories and custom taxonomy terms through a simple drag-and-drop interface
Custom Taxonomy Sort Developer Profile
6 plugins · 1K total installs
How We Detect Custom Taxonomy Sort
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-taxonomy-sort/css/custom-taxonomy-sort.css/wp-content/plugins/custom-taxonomy-sort/js/custom-taxonomy-sort.js/wp-content/plugins/custom-taxonomy-sort/js/custom-taxonomy-sort.jscustom-taxonomy-sort/js/custom-taxonomy-sort.js?ver=custom-taxonomy-sort/css/custom-taxonomy-sort.css?ver=HTML / DOM Fingerprints
id="tax-order"name="tax-order"aria-required="true"