
SortMeThis Security & Risk Analysis
wordpress.org/plugins/sort-me-thisManage your WordPress media in a deeper and more precise way!
Is SortMeThis Safe to Use in 2026?
Generally Safe
Score 100/100SortMeThis has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sort-me-this" plugin v1.1 presents a significant security risk primarily due to a large attack surface composed entirely of unprotected AJAX handlers. While the plugin demonstrates good practices by using prepared statements for SQL and avoiding dangerous functions or file operations, the lack of authorization checks on all 16 AJAX entry points is a critical oversight. This means any authenticated user, regardless of their role or capabilities, could potentially trigger these handlers and manipulate the plugin's functionality.
Taint analysis reveals flows with unsanitized paths, indicating a potential for path traversal vulnerabilities, though no critical or high severity issues were flagged. This is concerning because even if no immediate critical exploits are evident, the presence of unsanitized paths is a foundational weakness that could be leveraged with specific inputs. The absence of any recorded vulnerability history might suggest a lack of past exploitation or discovery, but this should not be interpreted as an indication of current robust security, especially given the identified code weaknesses.
In conclusion, the plugin has some positive security attributes, such as the use of prepared statements. However, the overwhelming number of unprotected AJAX endpoints and the taint analysis findings create a substantial risk. The plugin's security posture is poor due to the exposed attack surface. Remediation should prioritize adding proper authentication and capability checks to all AJAX handlers.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Limited capability checks
- Output escaping is insufficient (55% unescaped)
SortMeThis Security Vulnerabilities
SortMeThis Code Analysis
Output Escaping
Data Flow Analysis
SortMeThis Attack Surface
AJAX Handlers 16
WordPress Hooks 6
Maintenance & Trust
SortMeThis Maintenance & Trust
Maintenance Signals
Community Trust
SortMeThis Alternatives
Media Library Organizer – WordPress Media Library Folders & File Manager
media-library-organizer
Create unlimited Media Library folders and subfolders to organize your files. Export Media Library folders, set default attributes & more.
Media Library Folders
media-library-plus
Easier file and folder management for WordPress Media Library for Galleries and Albums
WP Media Category Management
wp-media-category-management
A plugin to provide bulk category management functionality for media in WordPress sites.
AzDrive – WordPress Media Folders & Organizer
azdrive
Organize your media library with folders and subfolders. Drag & drop files, color folders, sort and import from other plugins.
MediaSpark – Organize Your Media Library
mediaspark
Organize your WordPress media with folders, tags, and bulk editing. Auto alt text, analytics dashboard, and beautiful interface.
SortMeThis Developer Profile
2 plugins · 0 total installs
How We Detect SortMeThis
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sort-me-this/css/sort-me-this-admin.css/wp-content/plugins/sort-me-this/selectize/dist/css/selectize.css/wp-content/plugins/sort-me-this/css/jquery-ui.css/wp-content/plugins/sort-me-this/js/sort-me-this-admin.js/wp-content/plugins/sort-me-this/selectize/dist/js/standalone/selectize.min.js/wp-content/plugins/sort-me-this/partials/img/sortmethis_icon.pngselectize/dist/css/selectize.csscss/jquery-ui.cssjs/sort-me-this-admin.jsselectize/dist/js/standalone/selectize.min.jspartials/img/sortmethis_icon.pngsort-me-this/css/sort-me-this-admin.css?ver=sort-me-this/js/sort-me-this-admin.js?ver=HTML / DOM Fingerprints
smt-curr-pageThe Sort_Me_This_Loader will then create the relationship
between the defined hooks and the functions defined in this
class.smt-curr-pagesmet_retrieve_infosmet_edit_metadatasmet_save_cat_onlysmet_show_filtered_mediasmet_save_new_media_categorysmet_delete_media_category+2 more