Post Meta Box Order Security & Risk Analysis

wordpress.org/plugins/post-meta-box-order

Easily change the order of the meta boxes on the posts screen.

10 active installs v2.0 PHP + WP 3.0+ Updated Jul 10, 2016
meta-boxmetaboxmultisiteorderposts-metabox
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post Meta Box Order Safe to Use in 2026?

Generally Safe

Score 85/100

Post Meta Box Order has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The static analysis of the "post-meta-box-order" plugin v2.0 indicates a generally strong security posture based on the provided data. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, or external HTTP requests is commendable. Furthermore, the plugin appears to have no traceable taint flows, suggesting that data sanitation and handling are robust.

The vulnerability history also reflects positively, with no known CVEs, past or present. This lack of past vulnerabilities, combined with the clean static analysis, suggests a mature and well-maintained codebase. The plugin's minimal attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, further contributes to its security.

However, a notable absence of any nonce checks or capability checks across its entry points is a significant concern. While the current analysis shows no direct vulnerabilities, this lack of authorization checks could potentially expose the plugin to CSRF or privilege escalation if new entry points were introduced or if existing behavior could be manipulated by unauthenticated users. The overall conclusion is that the plugin is currently secure based on the provided data, but the lack of authentication mechanisms for any potential interactions is a potential area for future risk.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Post Meta Box Order Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Post Meta Box Order Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Post Meta Box Order Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitpost-meta-box-order.php:54
Maintenance & Trust

Post Meta Box Order Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedJul 10, 2016
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Post Meta Box Order Developer Profile

Mustafa Uysal

9 plugins · 20K total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Post Meta Box Order

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-meta-box-order/

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Post Meta Box Order