
Sorted – Post & Taxonomy Reorder Security & Risk Analysis
wordpress.org/plugins/sorted-post-taxonomy-reorderEasily reorder posts, pages, and taxonomies with a simple drag-and-drop interface directly from your WordPress dashboard.
Is Sorted – Post & Taxonomy Reorder Safe to Use in 2026?
Generally Safe
Score 100/100Sorted – Post & Taxonomy Reorder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sorted-post-taxonomy-reorder" plugin version 1.0 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping nearly all output. The absence of known CVEs and a clean vulnerability history are also strong indicators of a well-maintained and secure plugin. Furthermore, all identified entry points, including AJAX handlers, appear to have nonce checks in place, which is a crucial security measure.
However, the static analysis reveals a significant concern regarding the use of the `unserialize` function. This function is notoriously dangerous as it can lead to Remote Code Execution (RCE) if an attacker can control the data being unserialized. While there are no direct indicators of immediate exploitation in the taint analysis (no critical or high severity flows), the presence of `unserialize` without apparent sanitization or strict input validation for the unserialized data represents a potential attack vector. The taint analysis also indicates that three out of four flows have unsanitized paths, which, while not classified as critical or high, suggests a potential for subtle vulnerabilities if the data sources are not tightly controlled.
In conclusion, while the plugin benefits from a lack of known vulnerabilities and adherence to many secure coding practices, the indiscriminate use of `unserialize` is a notable weakness. This, coupled with the presence of unsanitized paths in the taint analysis, necessitates careful attention to how data is handled by this plugin. Developers should prioritize validating and sanitizing any data before passing it to `unserialize` to mitigate the risk of potential exploits.
Key Concerns
- Dangerous function used (unserialize)
- Flows with unsanitized paths detected
Sorted – Post & Taxonomy Reorder Security Vulnerabilities
Sorted – Post & Taxonomy Reorder Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Sorted – Post & Taxonomy Reorder Attack Surface
AJAX Handlers 4
WordPress Hooks 10
Maintenance & Trust
Sorted – Post & Taxonomy Reorder Maintenance & Trust
Maintenance Signals
Community Trust
Sorted – Post & Taxonomy Reorder Alternatives
Custom Category Post Order
custom-post-order-category
Order your post by category or custom post type by drag & drop interface.
Bracket Post Order
bracket-post-order
Drag-and-drop ordering for posts, pages, custom post types, and taxonomy terms — with per-category post ordering.
Real Custom Post Order: Create a custom order for your content
real-custom-post-order
Custom post order for posts, pages, WooCommerce products and custom post types using drag and drop. Simple and intuitive sorting of your content!
Custom Reorder Manager
custom-reorder-manager
Reorder WordPress posts with drag & drop mechanism.
GAP3 Coders Taxonomy Post Order
gap3coders-taxonomy-post-order
Easily reorder posts within taxonomy terms using drag-and-drop interface. Custom order automatically applies to frontend without any code changes.
Sorted – Post & Taxonomy Reorder Developer Profile
40 plugins · 25K total installs
How We Detect Sorted – Post & Taxonomy Reorder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sorted-post-taxonomy-reorder/assets/css/sortptr-style.css/wp-content/plugins/sorted-post-taxonomy-reorder/assets/css/jquery-ui.css/wp-content/plugins/sorted-post-taxonomy-reorder/assets/js/sortptr-script.js/wp-content/plugins/sorted-post-taxonomy-reorder/assets/js/sortptr-sortable-ui.jsassets/js/sortptr-script.jsassets/js/sortptr-sortable-ui.jssorted-post-taxonomy-reorder/assets/css/sortptr-style.css?ver=sorted-post-taxonomy-reorder/assets/css/jquery-ui.css?ver=sorted-post-taxonomy-reorder/assets/js/sortptr-script.js?ver=sorted-post-taxonomy-reorder/assets/js/sortptr-sortable-ui.js?ver=HTML / DOM Fingerprints
data-sortptr-noncesortptr_ajax_object