
Advanced Random Posts Security & Risk Analysis
wordpress.org/plugins/advanced-random-postsDisplay random posts from selected categories or current category or all posts with thumbnail images (optional).
Is Advanced Random Posts Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Random Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The advanced-random-posts v2.3 plugin exhibits a mixed security posture. On the positive side, there are no known historical vulnerabilities (CVEs) and the code appears to be free of critical taint analysis issues, SQL injection risks, and direct file operations. All SQL queries utilize prepared statements, which is a significant strength. However, several concerning practices are evident in the static analysis.
A primary concern is the use of the deprecated `create_function` within the code, which is a known security risk as it allows for dynamic code execution and can be a vector for various injection attacks. Additionally, a significant portion of the output (70%) is not properly escaped, meaning user-supplied data displayed on the frontend could be vulnerable to cross-site scripting (XSS) attacks. The complete absence of nonce checks and capability checks across all entry points, though the entry point count is zero, is a potential weakness if any new entry points are introduced without proper security considerations.
Given the lack of historical vulnerabilities and the absence of critical taint flows, the overall immediate risk might seem low. However, the presence of `create_function` and the high rate of unescaped output represent significant latent risks that could be exploited. The plugin's security strengths lie in its handling of database queries, but its weaknesses in dynamic code execution and output sanitization warrant attention.
Key Concerns
- Use of dangerous function create_function
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Advanced Random Posts Security Vulnerabilities
Advanced Random Posts Code Analysis
Dangerous Functions Found
Output Escaping
Advanced Random Posts Attack Surface
WordPress Hooks 1
Maintenance & Trust
Advanced Random Posts Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Random Posts Alternatives
Advanced Random Posts Widget
advanced-random-posts-widget
Provides flexible and advanced random posts. Display it via shortcode or widget with thumbnails, post excerpt, and much more!
Smart Recent Posts Widget
smart-recent-posts-widget
Provides advanced recent posts widget,you can display it with thumbnails, excerpt, date, author, comment count and more.
Latest Posts
latest-posts
Latest posts widget to display recent posts from category.
Random Post for Widget
random-post-for-widget
This simple plugin is a widget that displays a list of random posts on your sidebar. You can exclude certain posts by ID.
Random Posts and Pages Widget
ays-random-posts-and-pages
The main advantage of this widget is random movement of random links and every time they are changing.
Advanced Random Posts Developer Profile
4 plugins · 660 total installs
How We Detect Advanced Random Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-random-posts/js/adv-random-posts.js/wp-content/plugins/advanced-random-posts/css/adv-random-posts.css/wp-content/plugins/advanced-random-posts/js/adv-random-posts.jsadvanced-random-posts/js/adv-random-posts.js?ver=advanced-random-posts/css/adv-random-posts.css?ver=HTML / DOM Fingerprints
widget_advancedrandompostsid="advancedrandomposts"name="advancedrandomposts"yg_adv_random_posts