
ReOrder Posts within Categories Security & Risk Analysis
wordpress.org/plugins/reorder-post-within-categoriesEnables manual ranking of post (and custom post) within taxonomy terms using a drag & drop grid interface.
Is ReOrder Posts within Categories Safe to Use in 2026?
Generally Safe
Score 85/100ReOrder Posts within Categories has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'reorder-post-within-categories' v2.14.5 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query sanitization (84% prepared statements) and output escaping (97%), with no known historical vulnerabilities. This suggests a developer who is generally aware of secure coding principles.
However, significant concerns arise from the attack surface analysis. A total of four AJAX handlers are present, and alarmingly, all four lack authentication checks. This creates a wide entry point for potential attackers to interact with the plugin's functionality without proper authorization. Furthermore, the taint analysis reveals three high-severity flows with unsanitized paths. While the static analysis didn't flag dangerous functions or file operations, these high-severity taint flows indicate a potential for malicious data to be processed in an unsafe manner, which, when combined with the unprotected AJAX endpoints, poses a considerable risk.
In conclusion, while the absence of historical CVEs and good practices in SQL and output handling are strengths, the plugin's current state is weakened by its substantial, unprotected attack surface via AJAX and the presence of high-severity unsanitized taint flows. These critical weaknesses necessitate immediate attention to mitigate potential security breaches.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
ReOrder Posts within Categories Security Vulnerabilities
ReOrder Posts within Categories Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ReOrder Posts within Categories Attack Surface
AJAX Handlers 4
WordPress Hooks 19
Maintenance & Trust
ReOrder Posts within Categories Maintenance & Trust
Maintenance Signals
Community Trust
ReOrder Posts within Categories Alternatives
Pre-Orders for WooCommerce
pre-orders-for-woocommerce
Ultimate Pre-Orders Plugin for WooCommerce.
YITH Pre-Order for WooCommerce
yith-pre-order-for-woocommerce
Let your customers buy products before they are released and generate cash flow in advance to cover costs.
One Click Order Re-Order
one-click-order-reorder
Place any previous WooCommerce orders again into cart without any restrictions of orders status by just ONE CLICK.
Pre-Orders – Extended Stock Status for WooCommerce
pre-orders-wc
Just another product stock status for your WooCommerce store.
Custom Reorder Manager
custom-reorder-manager
Reorder WordPress posts with drag & drop mechanism.
ReOrder Posts within Categories Developer Profile
6 plugins · 25K total installs
How We Detect ReOrder Posts within Categories
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reorder-post-within-categories/admin/css/reorder-post-within-categories-admin.css/wp-content/plugins/reorder-post-within-categories/assets/jquery-ui.min.css/wp-content/plugins/reorder-post-within-categories/assets/sortable/Sortable.min.js/wp-content/plugins/reorder-post-within-categories/admin/js/reorder-post-within-categories-admin.js//code.jquery.com/ui/1.12.1/themes/base/jquery-ui.min.css//cdn.jsdelivr.net/npm/sortablejs@latest/Sortable.min.jsreorder-post-within-categories-admin.css?ver=reorder-post-within-categories-admin.js?ver=HTML / DOM Fingerprints
rpwc2-order-type-select NB @since 2.9.0 flag terms with v1.x rankings if required.data-rpwc-iddata-rpwc-orderrpwc2/wp-json/reorder-post-within-categories/v1/settings