70
Intuitive Custom Post Order
Easy sorting that might just break your database.
HealthyGrowing
70/100
Simple sorting works well until your database grows or a security vulnerability appears.
Active installs
~450,000
our estimate · wp.org shows 400k+
Rating
4.4★
140 ratings
Trend · vs a year ago
+53%
Growing fast
196 → 299 installs/day
What to watch out for
- MINORnot updated in 9 months
Downloads over time
real new installs per day · release spikes shown separately from the trend2025-04-302025-08-082025-11-162026-02-232026-06-03
organicrelease spikerelease tailorganic trend · 14d rolling median
Growing fast · +53% in the last year
196/day a year ago→299/day today
Reviews
what people actually sayIntuitive Custom Post Order is a well-liked drag-and-drop reordering plugin for posts, pages, and custom post types, but it carries meaningful caveats around a known SQL injection vulnerability, compatibility issues with newer WordPress versions and multisite, and severe database performance problems on large sites.
What people like
- +Simple drag-and-drop reordering works reliably for posts, pages, and custom post types×5
- +Works with custom taxonomies and third-party plugins like WPML×2
- +Considered easy and effective to use with minimal setup×3
Common complaints
- −SQL injection vulnerability reported by both Wordfence and iThemes Security (since 3.1.4.1)×2
- −Causes severe database performance degradation on large sites — updates every post's menu_order on each reorder, generating thousands of DB queries
- −Not working on WordPress 6.5.4
- −Broken on multisite installations; plugin appears abandoned
- −Can leave multiple posts with the same order value, causing incorrect front-end sort order
- −Conflicts with other post-ordering plugins (e.g. Simple Custom Post Order), breaking manual sorting
Review trustReviews look organic
- 4.42★Verified rating — holds steady vs the raw 4.40★
- 8%One-shot reviewers — most reviewers are active community members
Reviews per month · 5★ vs lower
2024-07-142025-07-092026-06-04
5★ reviews1–4★ reviews
All-time ratings · 140 total
Latest reviews · 90 analyzed
- 2026-04-10★★★★★Incompatible with “Simple Custom Post Order”freakqnc
- 2026-02-25★★★★★The best plugin for sorting posts, taxonomies, and moremegane9988
- 2025-10-24★★★★★Super extentionjcmais40
- 2024-10-23★★★★★It's really goodErik Eliasson
- 2024-06-24★★★★★動かないkayaman1-shot
- 2023-05-12★★★★★Same here with iThemes Security – SQL Injection vulnerability !!!ToTTi
- 2023-03-29★★★★★SQL Injection vulnerability !!!metaeditor
- 2021-04-13★★★★★sehr gut.franziskaner63
- 2020-05-04★★★★★Broken with multisite and yoastRobert
- 2020-04-14★★★★★Awesome PluginAkhtarujjaman Shuvo
Releases
recent versions from WordPress.org SVNFor developers & the curious
the raw signals behind the grade — none of this is on the friendly summary aboveDownload signals
Baselines are computed on organic days only — release spikes and their tails are excluded, so they're not inflated by the auto-update wave.
672
Baseline · median of last 7 organic days
317
Prior 7-day baseline
392
Floor · 25th percentile over 14 days
850
Mean release-day peak (30d)
732
Latest day · 2026-06-03(organic)
+112.0%
Week-over-week organic trend
Review signals
Concentration and drive-by metrics drive the review-burst and fake-review flags. 30–40% solo reviewers is normal; we only flag the extremes.
20%
Max month share · biggest single 30-day window
1.95
Distribution CV · <0.6 even, >1.5 bursty
81%
5★ share in analyzed sample
8%
Solo reviewers · only this one wp.org activity
—
Volume velocity · last 6mo vs prior 6mo
4.34 → 4.42★
Sample avg · raw → solo-filtered