
WP Term Order Security & Risk Analysis
wordpress.org/plugins/wp-term-orderSort taxonomy terms, your way.
Is WP Term Order Safe to Use in 2026?
Generally Safe
Score 99/100WP Term Order has a strong security track record. Known vulnerabilities have been patched promptly.
The 'wp-term-order' plugin v2.2.0 demonstrates a generally good security posture with robust use of nonce and capability checks on its identified entry points. The static analysis reveals a very small attack surface, with no unprotected AJAX handlers, shortcodes, cron events, or REST API routes. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is positive. The taint analysis also indicates no immediate vulnerabilities with unsanitized paths.
However, a significant concern arises from the SQL query handling. Both SQL queries within the plugin are not using prepared statements, which introduces a potential risk of SQL injection, especially if the inputs feeding these queries are not meticulously sanitized. While the output escaping is largely effective, this SQL vulnerability remains a notable weakness.
The vulnerability history, while showing no currently unpatched CVEs, does reveal a past medium-severity vulnerability, specifically Cross-Site Request Forgery (CSRF). The fact that a past vulnerability existed, even if patched, suggests that thorough auditing and secure coding practices are crucial to prevent recurrence. The plugin's strengths lie in its limited attack surface and strong authentication/authorization checks, but the lack of prepared statements for SQL queries is a clear area requiring immediate attention.
Key Concerns
- Raw SQL queries without prepared statements
WP Term Order Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Term Order <= 2.1.0 - Cross-Site Request Forgery
WP Term Order Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Term Order Attack Surface
AJAX Handlers 1
WordPress Hooks 13
Maintenance & Trust
WP Term Order Maintenance & Trust
Maintenance Signals
Community Trust
WP Term Order Alternatives
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
Custom Taxonomy Order
custom-taxonomy-order-ne
Allows for the ordering of categories and custom taxonomy terms through a simple drag-and-drop interface
Post Terms Order – per Post based
post-terms-order
Sort Taxonomy Terms per Post basis using a Drag and Drop Sortable JavaScript capability.
I Order Terms
i-order-terms
Allows theme developers to add order/sort functionality for categories, tags and custom taxonomies.
WP Category Sort
wp-category-sort
The WP Category Sort plugin allows you to easily reorder your categories the way you want via drag and drop.
WP Term Order Developer Profile
28 plugins · 332K total installs
How We Detect WP Term Order
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-term-order/js/quick-edit.js/wp-content/plugins/wp-term-order/js/reorder.js/wp-content/plugins/wp-term-order/js/quick-edit.js/wp-content/plugins/wp-term-order/js/reorder.jswp-term-order/js/quick-edit.js?ver=wp-term-order/js/reorder.js?ver=HTML / DOM Fingerprints
data-term-idwpTermOrder/wp-json/wp-term-order/v1/term/reorder