
Better Random Redirect Security & Risk Analysis
wordpress.org/plugins/better-random-redirectBased on the original Random Redirect, this plugin enables efficient, easy random redirection to a post. Supports setting a category for all random re …
Is Better Random Redirect Safe to Use in 2026?
Mostly Safe
Score 78/100Better Random Redirect is generally safe to use. 1 past CVE were resolved. Keep it updated.
The plugin 'better-random-redirect' v1.3.20 presents a mixed security posture. On the positive side, the code analysis indicates good practices in handling SQL queries, with all 7 queries utilizing prepared statements, and no dangerous functions or file operations were detected. The attack surface is also relatively small, with only one shortcode identified and no AJAX handlers or REST API routes present. However, there are significant concerns, particularly regarding output escaping and the lack of security checks. Only 6% of the 17 detected outputs are properly escaped, leaving a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the absence of nonce checks and capability checks on the identified entry point (the shortcode) is a critical oversight, meaning any user, regardless of their role, could potentially trigger its functionality. The vulnerability history reveals a past medium-severity XSS vulnerability, and the fact that one CVE is currently unpatched is a serious red flag, suggesting ongoing security risks that have not been addressed by the developers. While the plugin demonstrates some secure coding practices, the high percentage of unescaped output and the complete lack of security checks on its primary entry point, coupled with an unpatched vulnerability, create a notable risk profile that requires immediate attention.
Key Concerns
- Unpatched CVE
- Unescaped output
- Missing nonce checks
- Missing capability checks
- Taint flows with unsanitized paths
Better Random Redirect Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Better Random Redirect <= 1.3.20 - Authenticated (Administrator+) Stored Cross-Site Scripting
Better Random Redirect Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Better Random Redirect Attack Surface
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Better Random Redirect Maintenance & Trust
Maintenance Signals
Community Trust
Better Random Redirect Alternatives
Advanced Random Posts
advanced-random-posts
Display random posts from selected categories or current category or all posts with thumbnail images (optional).
Random Related Posts Based on Category
random-related-posts-based-on-category
This plugin allows you to list any number of related posts from the same category as the current post. You can also randomise these results.
Show Category Posts Fade in/out
show-posts-fade-inout-fix
The Random Featured Post plugin allows you to display a random post from a designated category as a "featured" post.
Category Posts Widget
category-posts
Adds a widget that shows the most recent posts from a single category.
Advanced Random Posts Widget
advanced-random-posts-widget
Provides flexible and advanced random posts. Display it via shortcode or widget with thumbnails, post excerpt, and much more!
Better Random Redirect Developer Profile
3 plugins · 61K total installs
How We Detect Better Random Redirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/better-random-redirect/css/brr_admin.css/wp-content/plugins/better-random-redirect/js/brr_admin.jsHTML / DOM Fingerprints
[random-url