
Real Custom Post Order: Create a custom order for your content Security & Risk Analysis
wordpress.org/plugins/real-custom-post-orderCustom post order for posts, pages, WooCommerce products and custom post types using drag and drop. Simple and intuitive sorting of your content!
Is Real Custom Post Order: Create a custom order for your content Safe to Use in 2026?
Generally Safe
Score 100/100Real Custom Post Order: Create a custom order for your content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "real-custom-post-order" plugin v1.3.130 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events without proper authorization checks significantly limits the potential attack surface. Furthermore, the lack of identified dangerous functions, file operations, external HTTP requests, and no critical or high severity taint flows are positive indicators. The plugin also demonstrates good practices in its SQL query handling, with 80% utilizing prepared statements.
However, a notable concern arises from the output escaping. With 100% of the identified outputs not being properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is rendered directly to the user interface without sanitization could be exploited. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a history of secure development or diligent patching, but this does not negate the immediate risk posed by the unescaped output in the current version.
In conclusion, while the plugin's architecture and handling of core security features like authentication and SQL queries appear robust, the lack of output escaping represents a critical weakness that needs immediate attention. Addressing this would solidify its security, but as it stands, the XSS risk is the primary concern.
Key Concerns
- Output not properly escaped
Real Custom Post Order: Create a custom order for your content Security Vulnerabilities
Real Custom Post Order: Create a custom order for your content Code Analysis
SQL Query Safety
Output Escaping
Real Custom Post Order: Create a custom order for your content Attack Surface
WordPress Hooks 3
Maintenance & Trust
Real Custom Post Order: Create a custom order for your content Maintenance & Trust
Maintenance Signals
Community Trust
Real Custom Post Order: Create a custom order for your content Alternatives
Custom Category Post Order
custom-post-order-category
Order your post by category or custom post type by drag & drop interface.
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
Simple Custom Post Order
simple-custom-post-order
Easily reorder posts, pages, custom post types, and taxonomies with intuitive drag-and-drop sorting in the WordPress admin.
Posts Order
category-custom-post-order
Order posts separately for each terms and taxonomies
My Post Order
my-posts-order
A plugin which allows you to sort posts, pages, custom post type in ANY order and display the same in your sidebar.
Real Custom Post Order: Create a custom order for your content Developer Profile
4 plugins · 210K total installs
How We Detect Real Custom Post Order: Create a custom order for your content
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/real-custom-post-order/dist/admin.css/wp-content/plugins/real-custom-post-order/dist/admin.js/wp-content/plugins/real-custom-post-order/dist/admin.jsreal-custom-post-order/dist/admin.css?ver=real-custom-post-order/dist/admin.js?ver=HTML / DOM Fingerprints
rcpo-post-order-screen-settingsdata-rcpo-post-typercpo/wp-json/devowl-wp/rcpo/v1/save-order