
Sortable Posts Security & Risk Analysis
wordpress.org/plugins/sortable-postsSortable Posts is a small plugin for WordPress that adds sortability to post types and taxonomies from the admin panel.
Is Sortable Posts Safe to Use in 2026?
Generally Safe
Score 85/100Sortable Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sortable-posts plugin v1.1.3 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the lack of any recorded vulnerabilities, including critical or high severity ones, is a very positive indicator. The plugin also shows no external HTTP requests or file operations, which are common vectors for exploitation.
However, there are areas for improvement. The most significant concern is the complete lack of prepared statements for the three identified SQL queries. This makes the plugin highly vulnerable to SQL injection if any part of the data used in these queries originates from user input. Additionally, with only 22% of output properly escaped, there's a substantial risk of cross-site scripting (XSS) vulnerabilities, as unsanitized output can be rendered by the browser.
While the plugin has no recorded vulnerability history, this should be viewed cautiously. It doesn't guarantee future security. The lack of nonce checks and limited capability checks also present potential weaknesses if the plugin were to introduce more complex entry points in the future. Overall, the plugin demonstrates good practice in minimizing its attack surface but suffers from critical flaws in database interaction and output sanitization that require immediate attention.
Key Concerns
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- No nonce checks implemented
Sortable Posts Security Vulnerabilities
Sortable Posts Code Analysis
SQL Query Safety
Output Escaping
Sortable Posts Attack Surface
WordPress Hooks 14
Maintenance & Trust
Sortable Posts Maintenance & Trust
Maintenance Signals
Community Trust
Sortable Posts Alternatives
Integration of Simple Custom Post Order and WP Rocket
scpo-wp-rocket-integration
Automatically cleans the WP Rocket cache when the posts order is changed.
Real Custom Post Order: Create a custom order for your content
real-custom-post-order
Custom post order for posts, pages, WooCommerce products and custom post types using drag and drop. Simple and intuitive sorting of your content!
Posts Order
category-custom-post-order
Order posts separately for each terms and taxonomies
My Post Order
my-posts-order
A plugin which allows you to sort posts, pages, custom post type in ANY order and display the same in your sidebar.
Reshuffle – Change Post Order, Product Order, Taxonomy Order
reshuffle
Reorder posts, products, and taxonomy terms via a drag-and-drop interface.
Sortable Posts Developer Profile
2 plugins · 180 total installs
How We Detect Sortable Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sortable-posts/assets/css/sortable-posts.css/wp-content/plugins/sortable-posts/assets/js/sortable-posts.js/wp-content/plugins/sortable-posts/assets/js/sortable-posts.jssortable-posts/assets/css/sortable-posts.css?ver=sortable-posts/assets/js/sortable-posts.js?ver=HTML / DOM Fingerprints
sortable-postssortable-posts-ordersortable-posts-order-positionsortable-posts-placeholderdata-sortable-postsWP_API_Settings/wp-json/sortable-posts/v1/update-order