
WP Sort Order Security & Risk Analysis
wordpress.org/plugins/wp-sort-orderOrder terms (Users, Posts, Pages, Custom Post Types and Custom Taxonomies) using a Drag and Drop with jQuery ui Sortable.
Is WP Sort Order Safe to Use in 2026?
Generally Safe
Score 91/100WP Sort Order has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-sort-order plugin v1.3.5 exhibits a mixed security posture. On the positive side, it has a relatively small attack surface with all identified AJAX handlers protected by nonce checks. The absence of file operations and external HTTP requests is also a good sign. However, significant concerns arise from the code analysis, particularly regarding output escaping and SQL query practices. With nearly half of the output not being properly escaped, there's a notable risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, a substantial portion of SQL queries are not using prepared statements, which could lead to SQL injection vulnerabilities if these queries are not properly sanitized. The vulnerability history, while currently showing no unpatched CVEs, indicates a past medium-severity vulnerability, specifically missing authorization. This pattern, combined with the zero capability checks observed in the static analysis, suggests a recurring theme of authorization weaknesses that could be exploited.
Key Concerns
- Unescaped output detected
- SQL queries not using prepared statements
- Past medium vulnerability (missing authorization)
- No capability checks on entry points
- Flow with unsanitized path in taint analysis
WP Sort Order Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Sort Order <= 1.3.1 - Missing Authorization
WP Sort Order Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Sort Order Attack Surface
AJAX Handlers 4
WordPress Hooks 20
Maintenance & Trust
WP Sort Order Maintenance & Trust
Maintenance Signals
Community Trust
WP Sort Order Alternatives
Real Custom Post Order: Create a custom order for your content
real-custom-post-order
Custom post order for posts, pages, WooCommerce products and custom post types using drag and drop. Simple and intuitive sorting of your content!
Reshuffle – Change Post Order, Product Order, Taxonomy Order
reshuffle
Reorder posts, products, and taxonomy terms via a drag-and-drop interface.
Bracket Post Order
bracket-post-order
Drag-and-drop ordering for posts, pages, custom post types, and taxonomy terms — with per-category post ordering.
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
WP Sort Order Developer Profile
40 plugins · 33K total installs
How We Detect WP Sort Order
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-sort-order/css/fontawesome.min.css/wp-content/plugins/wp-sort-order/js/fontawesome.min.js/wp-content/plugins/wp-sort-order/js/bootstrap.min.js/wp-content/plugins/wp-sort-order/css/bootstrap.min.css/wp-content/plugins/wp-sort-order/js/front-scripts.jsjs/front-scripts.jsjs/fontawesome.min.jsjs/bootstrap.min.jswp-sort-order/js/front-scripts.js?ver=wp-sort-order/js/fontawesome.min.js?ver=wp-sort-order/css/fontawesome.min.css?ver=wp-sort-order/js/bootstrap.min.js?ver=wp-sort-order/css/bootstrap.min.css?ver=HTML / DOM Fingerprints
premiumdata-term_idwpso