
WP Order By Security & Risk Analysis
wordpress.org/plugins/wp-order-bySimple and easy way to order your posts, pages or any other custom post-type in a various options.
Is WP Order By Safe to Use in 2026?
Use With Caution
Score 64/100WP Order By has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "wp-order-by" v1.4.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no known dangerous functions, no file operations, no external HTTP requests, and all SQL queries utilizing prepared statements. The presence of capability checks is also a good sign. However, a significant concern arises from the output escaping analysis, where 0% of the 22 total outputs are properly escaped. This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of XSS-related CVEs.
The taint analysis, while showing a low number of flows, reveals that all analyzed flows have unsanitized paths. While no critical or high severity taint flows were identified, the presence of unsanitized paths is a precursor to potential vulnerabilities. The vulnerability history further amplifies these concerns, with one unpatched medium severity CVE directly related to XSS. The fact that the last vulnerability was in 2025 suggests a recent or ongoing security issue.
In conclusion, while the plugin has strengths in its handling of database queries and its limited attack surface, the pervasive lack of output escaping and the history of XSS vulnerabilities present a significant risk. The unpatched CVE and the taint analysis findings necessitate immediate attention to mitigate potential security breaches.
Key Concerns
- Unpatched CVE (medium severity)
- All analyzed taint flows have unsanitized paths
- 0% of outputs properly escaped
WP Order By Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Order By <= 1.4.2 - Reflected Cross-Site Scripting
WP Order By Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Order By Attack Surface
WordPress Hooks 10
Maintenance & Trust
WP Order By Maintenance & Trust
Maintenance Signals
Community Trust
WP Order By Alternatives
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
Simple Custom Post Order
simple-custom-post-order
Easily reorder posts, pages, custom post types, and taxonomies with intuitive drag-and-drop sorting in the WordPress admin.
Reorder Posts
metronet-reorder-posts
A simple and easy way to reorder your custom post types in WordPress.
ReOrder Posts within Categories
reorder-post-within-categories
Enables manual ranking of post (and custom post) within taxonomy terms using a drag & drop grid interface.
Reorder by Term
reorder-by-term
A simple and easy way to reorder your custom post types within terms in WordPress.
WP Order By Developer Profile
2 plugins · 190 total installs
How We Detect WP Order By
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-order-by/css/wpob.css/wp-content/plugins/wp-order-by/js/wpob.js/wp-content/plugins/wp-order-by/js/wpob.jswp-order-by/css/wpob.css?ver=wp-order-by/js/wpob.js?ver=HTML / DOM Fingerprints
posts_select_boxwpob-exclude-posts