
Unsortable Meta Box Security & Risk Analysis
wordpress.org/plugins/unsortable-meta-boxDisable dragging of meta boxes and reset their positions.
Is Unsortable Meta Box Safe to Use in 2026?
Generally Safe
Score 85/100Unsortable Meta Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "unsortable-meta-box" v0.9.0 plugin exhibits a strong security posture based on the provided static analysis. It demonstrates excellent practice by having zero AJAX handlers, REST API routes, shortcodes, or cron events, significantly reducing its attack surface. Furthermore, all identified SQL queries utilize prepared statements, preventing common SQL injection vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its secure design. The plugin also passes taint analysis with no identified critical or high severity flows, indicating robust sanitization and validation of data.
However, a notable concern arises from the limited output escaping, with only 40% of outputs being properly escaped. This leaves a potential window for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output without adequate sanitization. Additionally, the complete lack of nonce checks and capability checks across all entry points (though there are none) is a methodological gap. While the current lack of entry points mitigates immediate risk, if the plugin were to be extended in the future, these checks would be crucial to implement.
The vulnerability history of zero known CVEs, including none currently unpatched, is a very positive indicator of the plugin's past security. This suggests diligent development practices and a history of addressing any potential security flaws. In conclusion, "unsortable-meta-box" v0.9.0 is a well-coded plugin with a minimal attack surface and strong protection against common web vulnerabilities like SQL injection and XSS from tainted inputs. The primary area for improvement is the consistent and proper escaping of all outputs to mitigate potential XSS risks.
Key Concerns
- Output escaping is not consistently applied
- No nonce checks implemented
- No capability checks implemented
Unsortable Meta Box Security Vulnerabilities
Unsortable Meta Box Code Analysis
SQL Query Safety
Output Escaping
Unsortable Meta Box Attack Surface
WordPress Hooks 9
Maintenance & Trust
Unsortable Meta Box Maintenance & Trust
Maintenance Signals
Community Trust
Unsortable Meta Box Alternatives
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Ocean Extra
ocean-extra
Ocean Extra adds extra features and flexibility to the OceanWP theme for a turbocharged experience.
OptionTree
option-tree
Theme Options UI Builder for WordPress. A simple way to create & save Theme Options and Meta Boxes for free or premium themes.
MB Elementor Integration
mb-elementor-integrator
Integrates Meta Box's custom fields with Elementor page builder via dynamic tags.
Attesa Extra
attesa-extra
Add extra features to Attesa WordPress theme
Unsortable Meta Box Developer Profile
6 plugins · 4K total installs
How We Detect Unsortable Meta Box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/unsortable-meta-box/assets/css/admin.css/wp-content/plugins/unsortable-meta-box/assets/js/admin.js/wp-content/plugins/unsortable-meta-box/assets/js/admin.jsunsortable-meta-box/assets/css/admin.css?ver=unsortable-meta-box/assets/js/admin.js?ver=