
In category Order Security & Risk Analysis
wordpress.org/plugins/in-category-orderThis plugin lets you set the order of posts on a category basis with a simple Drag N Drop interface.
Is In category Order Safe to Use in 2026?
Generally Safe
Score 85/100In category Order has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "in-category-order" v0.0.2 plugin exhibits a generally positive security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the code demonstrates good practice by utilizing prepared statements for all SQL queries and not performing file operations or external HTTP requests. The lack of any identified dangerous functions or taint flows further reinforces this positive assessment.
However, a significant concern arises from the limited output escaping. With 37 total outputs and only 43% properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks across any potential entry points (though none were identified in this analysis) also represents a potential weakness if the plugin were to evolve and introduce such features without proper security considerations. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a history of secure development, but this does not mitigate the identified code-level risks.
In conclusion, while the plugin has strong foundational security by minimizing its attack surface and handling database interactions securely, the poor output escaping is a critical flaw that exposes users to XSS attacks. The lack of explicit authorization checks on potential future entry points is a minor concern given the current zero attack surface, but should be addressed if the plugin's functionality expands.
Key Concerns
- Low output escaping percentage
- No capability checks
- No nonce checks
In category Order Security Vulnerabilities
In category Order Release Timeline
In category Order Code Analysis
Output Escaping
In category Order Attack Surface
WordPress Hooks 7
Maintenance & Trust
In category Order Maintenance & Trust
Maintenance Signals
Community Trust
In category Order Alternatives
GR Order Category Post
gr-order-category-post
This plugin let you change the order from a category to an alphabetical order (A-Z).
Reshuffle – Change Post Order, Product Order, Taxonomy Order
reshuffle
Reorder posts, products, and taxonomy terms via a drag-and-drop interface.
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
In category Order Developer Profile
19 plugins · 9K total installs
How We Detect In category Order
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/in-category-order/assets/js/in_category_order.js/wp-content/plugins/in-category-order/assets/css/in_category_order.css/wp-content/plugins/in-category-order/assets/js/in_category_order.js/wp-content/plugins/in-category-order/assets/js/in_category_order.js?ver=/wp-content/plugins/in-category-order/assets/css/in_category_order.css?ver=HTML / DOM Fingerprints
in-category-order-tablein-category-order-rowin-category-order-titlein-category-order-remove-btnin-category-order-thumbnailin-category-order-iddata-in-cat-order-term-idin_cat_order