
Simple Custom Post Order Security & Risk Analysis
wordpress.org/plugins/simple-custom-post-orderEasily reorder posts, pages, custom post types, and taxonomies with intuitive drag-and-drop sorting in the WordPress admin.
Is Simple Custom Post Order Safe to Use in 2026?
Generally Safe
Score 99/100Simple Custom Post Order has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "simple-custom-post-order" v2.6.0 plugin exhibits a generally good security posture, with strong adherence to common WordPress security best practices. The static analysis reveals a clean codebase with no critical or high-severity taint flows, no dangerous functions, and a high percentage of SQL queries utilizing prepared statements and properly escaped output. The absence of file operations and external HTTP requests further mitigates common attack vectors. Crucially, all identified entry points, including the 5 AJAX handlers, have corresponding nonce and capability checks, indicating a robust defense against unauthorized access and manipulation of core functionalities.
Despite the positive static analysis, the plugin's vulnerability history warrants attention. A single medium-severity CVE was recorded recently, which is currently patched, but its presence suggests that the plugin, even with its good coding practices, has been a target or susceptible to vulnerabilities in the past. The common vulnerability type being 'Missing Authorization' in the past, although not present in the current version's static analysis, implies a historical weakness that required patching. Overall, while the current version appears secure based on static analysis and the lack of unpatched vulnerabilities, users should remain vigilant and ensure timely updates to address any future security advisories, as past issues indicate potential areas of concern.
The plugin demonstrates strong foundational security with proper use of prepared statements and output escaping. The robust implementation of nonce and capability checks on all identified entry points is commendable and significantly reduces the risk of common web vulnerabilities. The absence of dangerous functions, file operations, and external requests further strengthens its security profile. The only notable area for consideration is the historical vulnerability, which, although patched, highlights the importance of continuous monitoring and prompt updates for this plugin.
Key Concerns
- Recently patched medium severity CVE
Simple Custom Post Order Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Custom Post Order <= 2.5.7 - Missing Authorization
Simple Custom Post Order Release Timeline
Simple Custom Post Order Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Simple Custom Post Order Attack Surface
AJAX Handlers 5
WordPress Hooks 21
Maintenance & Trust
Simple Custom Post Order Maintenance & Trust
Maintenance Signals
Community Trust
Simple Custom Post Order Alternatives
Custom Category Post Order
custom-post-order-category
Order your post by category or custom post type by drag & drop interface.
Real Custom Post Order: Create a custom order for your content
real-custom-post-order
Custom post order for posts, pages, WooCommerce products and custom post types using drag and drop. Simple and intuitive sorting of your content!
Posts Order
category-custom-post-order
Order posts separately for each terms and taxonomies
My Post Order
my-posts-order
A plugin which allows you to sort posts, pages, custom post type in ANY order and display the same in your sidebar.
Sortable Posts
sortable-posts
Sortable Posts is a small plugin for WordPress that adds sortability to post types and taxonomies from the admin panel.
Simple Custom Post Order Developer Profile
11 plugins · 420K total installs
How We Detect Simple Custom Post Order
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-custom-post-order/assets/js/jquery.nicescroll.min.js/wp-content/plugins/simple-custom-post-order/assets/js/jquery-ui.min.js/wp-content/plugins/simple-custom-post-order/assets/js/script.js/wp-content/plugins/simple-custom-post-order/assets/css/style.css/wp-content/plugins/simple-custom-post-order/assets/css/custom.css/wp-content/plugins/simple-custom-post-order/assets/js/jquery.nicescroll.min.js/wp-content/plugins/simple-custom-post-order/assets/js/jquery-ui.min.js/wp-content/plugins/simple-custom-post-order/assets/js/script.jssimple-custom-post-order/assets/css/style.css?ver=simple-custom-post-order/assets/css/custom.css?ver=simple-custom-post-order/assets/js/jquery.nicescroll.min.js?ver=simple-custom-post-order/assets/js/jquery-ui.min.js?ver=simple-custom-post-order/assets/js/script.js?ver=HTML / DOM Fingerprints
scpo-noticescporder-js<!-- Simple Custom Post Order Settings --><!-- Simple Custom Post Order Settings --><!-- Simple Custom Post Order Settings -->data-scporder-save-settingsdata-scporder-reset-orderdata-scporder-post-typedata-scporder-taxonomydata-scporder-dismiss-noncedata-scporder-reset-noncescporder_ajax_objectscporder_nonce