
Post Order Control – Drag, Drop & Reorder Posts and Post Types Security & Risk Analysis
wordpress.org/plugins/post-order-controlDrag-and-drop ordering for any post type using WordPress's built-in menu_order field. Features modern admin UI and full theme compatibility.
Is Post Order Control – Drag, Drop & Reorder Posts and Post Types Safe to Use in 2026?
Generally Safe
Score 100/100Post Order Control – Drag, Drop & Reorder Posts and Post Types has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The post-order-control plugin v1.0.0 demonstrates a generally good security posture with no recorded vulnerabilities and strong practices in critical areas like SQL query sanitization. The plugin utilizes prepared statements for all its SQL queries, which significantly mitigates the risk of SQL injection attacks. Furthermore, it implements nonce and capability checks for many of its entry points, indicating an awareness of common WordPress security mechanisms. The absence of critical or high severity taint flows further supports its current safety. However, there are areas for improvement. The plugin exposes one unprotected REST API route, which could be a potential entry point for unauthorized access or manipulation if sensitive data or functionality is exposed. Additionally, a notable percentage (67%) of its output is not properly escaped, presenting a moderate risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly rendered in the output without sanitization. While the vulnerability history is clean, the lack of rigorous output escaping, coupled with the unprotected REST API endpoint, suggests that future development should prioritize addressing these specific weaknesses to maintain a robust security profile.
Key Concerns
- REST API route without permission callbacks
- Significant percentage of unescaped output
Post Order Control – Drag, Drop & Reorder Posts and Post Types Security Vulnerabilities
Post Order Control – Drag, Drop & Reorder Posts and Post Types Release Timeline
Post Order Control – Drag, Drop & Reorder Posts and Post Types Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Post Order Control – Drag, Drop & Reorder Posts and Post Types Attack Surface
AJAX Handlers 3
REST API Routes 1
WordPress Hooks 21
Maintenance & Trust
Post Order Control – Drag, Drop & Reorder Posts and Post Types Maintenance & Trust
Maintenance Signals
Community Trust
Post Order Control – Drag, Drop & Reorder Posts and Post Types Alternatives
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
Simple Custom Post Order
simple-custom-post-order
Easily reorder posts, pages, custom post types, and taxonomies with intuitive drag-and-drop sorting in the WordPress admin.
Simple Page Ordering
simple-page-ordering
Order your pages and other custom post types that support "page-attributes" with drag and drop right from the standard page list.
Reorder Posts
metronet-reorder-posts
A simple and easy way to reorder your custom post types in WordPress.
Reshuffle – Change Post Order, Product Order, Taxonomy Order
reshuffle
Reorder posts, products, and taxonomy terms via a drag-and-drop interface.
Post Order Control – Drag, Drop & Reorder Posts and Post Types Developer Profile
6 plugins · 420 total installs
How We Detect Post Order Control – Drag, Drop & Reorder Posts and Post Types
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-order-control/assets/css/wpu-opt-order.css/wp-content/plugins/post-order-control/assets/js/wpu-post-order-control.min.js/wp-content/plugins/post-order-control/assets/js/wpu-post-order-control.min.jspostordercontrol-orderpostordercontrol-order-scriptHTML / DOM Fingerprints
wpu-post-order-control-drag-handledata-post-order-controlwpApiSettings/wp-json/post-order-control/v1/posts/wp-json/post-order-control/v1/taxonomies