Simple Taxonomy Ordering Security & Risk Analysis

wordpress.org/plugins/simple-taxonomy-ordering

Quickly and easily reorder taxonomy terms with an easy to use and intuitive drag and drop interface.

20K active installs v2.3.4 PHP + WP 4.4+ Updated Mar 22, 2023
adminmetaordersimpleterm
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Taxonomy Ordering Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Taxonomy Ordering has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin 'simple-taxonomy-ordering' v2.3.4 demonstrates a generally good security posture based on the provided static analysis. The absence of critical or high severity taint flows, coupled with 100% output escaping and the use of prepared statements for a majority of its SQL queries, indicates that the developers are adhering to many secure coding practices. The single AJAX handler is also protected by a nonce check, further mitigating potential risks. The plugin also has no recorded vulnerability history, suggesting a stable and secure past.

However, a notable concern is the complete lack of capability checks on its entry points. While the AJAX handler has a nonce check, this does not prevent authenticated users from potentially accessing or manipulating the functionality if they possess insufficient privileges. A more robust security model would involve checking user capabilities to ensure only authorized roles can interact with plugin features. The presence of a bundled library (Select2) also introduces a dependency that, if outdated or containing vulnerabilities itself, could pose a risk, though this is not explicitly detailed in the provided data.

In conclusion, 'simple-taxonomy-ordering' v2.3.4 presents a low-risk profile due to its secure coding practices and lack of historical vulnerabilities. The primary area for improvement lies in the implementation of capability checks to enforce proper authorization. The absence of other common vulnerabilities like raw SQL queries or unescaped output is commendable.

Key Concerns

  • Missing capability checks on entry points
Vulnerabilities
None known

Simple Taxonomy Ordering Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Taxonomy Ordering Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
0
3 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

67% prepared3 total queries

Output Escaping

100% escaped3 total outputs
Attack Surface

Simple Taxonomy Ordering Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_yikes_sto_update_taxonomy_orderyikes-custom-taxonomy-order.php:59
WordPress Hooks 5
actioncurrent_screenyikes-custom-taxonomy-order.php:57
actioninityikes-custom-taxonomy-order.php:58
actionplugins_loadedyikes-custom-taxonomy-order.php:61
filterterms_clausesyikes-custom-taxonomy-order.php:108
filterterms_clausesyikes-custom-taxonomy-order.php:131
Maintenance & Trust

Simple Taxonomy Ordering Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMar 22, 2023
PHP min version
Downloads349K

Community Trust

Rating98/100
Number of ratings28
Active installs20K
Developer Profile

Simple Taxonomy Ordering Developer Profile

Evan Herman

15 plugins · 136K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
375 days
View full developer profile
Detection Fingerprints

How We Detect Simple Taxonomy Ordering

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-taxonomy-ordering/lib/css/yikes-tax-drag-drop.css/wp-content/plugins/simple-taxonomy-ordering/lib/js/yikes-tax-drag-drop.js
Script Paths
/wp-content/plugins/simple-taxonomy-ordering/lib/js/yikes-tax-drag-drop.js
Version Parameters
simple-taxonomy-ordering/lib/css/yikes-tax-drag-drop.css?ver=simple-taxonomy-ordering/lib/js/yikes-tax-drag-drop.js?ver=

HTML / DOM Fingerprints

CSS Classes
yikes-tax-drag-drop-wrap
HTML Comments
<!-- Simple Taxonomy Ordering Demo -->
Data Attributes
data-term-iddata-term-order
JS Globals
simple_taxonomy_ordering_data
FAQ

Frequently Asked Questions about Simple Taxonomy Ordering