
I Order Terms Security & Risk Analysis
wordpress.org/plugins/i-order-termsAllows theme developers to add order/sort functionality for categories, tags and custom taxonomies.
Is I Order Terms Safe to Use in 2026?
Generally Safe
Score 99/100I Order Terms has a strong security track record. Known vulnerabilities have been patched promptly.
The i-order-terms plugin version 1.5.3 exhibits a generally good security posture, with several positive indicators such as 100% of SQL queries using prepared statements and the presence of nonce and capability checks. The static analysis reveals a small attack surface with no immediately apparent unprotected entry points. File operations and external HTTP requests are also absent, which reduces potential attack vectors. However, a notable concern is that only 71% of output is properly escaped, leaving room for potential Cross-Site Scripting (XSS) vulnerabilities if the unescaped outputs are triggered by user-supplied data.
The vulnerability history shows one past medium-severity CVE, which was a Cross-Site Request Forgery (CSRF) vulnerability, and importantly, it is currently patched. This suggests that while vulnerabilities have existed, they have been addressed by the developers. The lack of critical or high-severity taint flows and dangerous functions in the static analysis is reassuring, indicating that the core code is likely not introducing inherent, severe risks. The absence of bundled libraries is also a positive as it avoids potential vulnerabilities from outdated dependencies.
In conclusion, i-order-terms v1.5.3 demonstrates strong adherence to several security best practices, particularly in database interaction and access control. The primary area for improvement lies in ensuring complete output escaping to mitigate XSS risks. The past CSRF vulnerability, now patched, indicates developer responsiveness to security issues. Overall, the plugin is in a relatively good security state, but the incomplete output escaping warrants attention.
Key Concerns
- Incomplete output escaping
I Order Terms Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
I Order Terms <= 1.5.0 - Cross-Site Request Forgery
I Order Terms Code Analysis
SQL Query Safety
Output Escaping
I Order Terms Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
I Order Terms Maintenance & Trust
Maintenance Signals
Community Trust
I Order Terms Alternatives
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
WP Category Sort
wp-category-sort
The WP Category Sort plugin allows you to easily reorder your categories the way you want via drag and drop.
The Taxonomy Sort
the-taxonomy-sort
Allows you to easily change the order of different taxonomies/terms/categories.
Post Terms Order – per Post based
post-terms-order
Sort Taxonomy Terms per Post basis using a Drag and Drop Sortable JavaScript capability.
Term Menu Order
term-menu-order
Creates a 'menu_order' column to specify term order, allowing theme and plugin developers to sort term by menu order.
I Order Terms Developer Profile
1 plugin · 1K total installs
How We Detect I Order Terms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/i-order-terms/code/assets/css/i-order-terms.css/wp-content/plugins/i-order-terms/code/assets/js/i-order-terms.jsi-order-terms/style.css?ver=i-order-terms.js?ver=HTML / DOM Fingerprints
i-order-terms-tableterm-order-inputi-order-terms-save-buttondata-taxonomydata-term-idi_order_terms