Real Custom Post Order: Create a custom order for your content Security & Risk Analysis

wordpress.org/plugins/real-custom-post-order

Custom post order for posts, pages, WooCommerce products and custom post types using drag and drop. Simple and intuitive sorting of your content!

9K active installs v1.3.130 PHP 7.4.0+ WP 5.9+ Updated Dec 2, 2025
custom-page-ordercustom-post-ordercustom-post-type-ordercustom-product-ordercustom-taxonomy-order
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Real Custom Post Order: Create a custom order for your content Safe to Use in 2026?

Generally Safe

Score 100/100

Real Custom Post Order: Create a custom order for your content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "real-custom-post-order" plugin v1.3.130 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events without proper authorization checks significantly limits the potential attack surface. Furthermore, the lack of identified dangerous functions, file operations, external HTTP requests, and no critical or high severity taint flows are positive indicators. The plugin also demonstrates good practices in its SQL query handling, with 80% utilizing prepared statements.

However, a notable concern arises from the output escaping. With 100% of the identified outputs not being properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is rendered directly to the user interface without sanitization could be exploited. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a history of secure development or diligent patching, but this does not negate the immediate risk posed by the unescaped output in the current version.

In conclusion, while the plugin's architecture and handling of core security features like authentication and SQL queries appear robust, the lack of output escaping represents a critical weakness that needs immediate attention. Addressing this would solidify its security, but as it stands, the XSS risk is the primary concern.

Key Concerns

  • Output not properly escaped
Vulnerabilities
None known

Real Custom Post Order: Create a custom order for your content Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Real Custom Post Order: Create a custom order for your content Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
4 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

80% prepared5 total queries

Output Escaping

0% escaped3 total outputs
Attack Surface

Real Custom Post Order: Create a custom order for your content Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_noticesinc\base\others\fallback-php-version.php:24
actionadmin_noticesinc\base\others\fallback-rest-api.php:29
actionadmin_noticesinc\base\others\fallback-wp-version.php:28
Maintenance & Trust

Real Custom Post Order: Create a custom order for your content Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version7.4.0
Downloads322K

Community Trust

Rating96/100
Number of ratings40
Active installs9K
Developer Profile

Real Custom Post Order: Create a custom order for your content Developer Profile

devowl.io GmbH

4 plugins · 210K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
402 days
View full developer profile
Detection Fingerprints

How We Detect Real Custom Post Order: Create a custom order for your content

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/real-custom-post-order/dist/admin.css/wp-content/plugins/real-custom-post-order/dist/admin.js
Script Paths
/wp-content/plugins/real-custom-post-order/dist/admin.js
Version Parameters
real-custom-post-order/dist/admin.css?ver=real-custom-post-order/dist/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
rcpo-post-order-screen-settings
Data Attributes
data-rcpo-post-type
JS Globals
rcpo
REST Endpoints
/wp-json/devowl-wp/rcpo/v1/save-order
FAQ

Frequently Asked Questions about Real Custom Post Order: Create a custom order for your content