Jet Random Members Widget Security & Risk Analysis

wordpress.org/plugins/jet-member-could

en: Create a cloud of users on your social network! Do you have many users? Do you want more communication? Install this widget!

10 active installs v1.3 PHP + WP + Updated Unknown
buddypressmembersmetawidgetwordpress-mu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Jet Random Members Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Jet Random Members Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "jet-member-could" v1.3 plugin exhibits a concerning security posture primarily due to its lack of output escaping and the presence of a dangerous function. While the plugin has no recorded vulnerabilities and utilizes prepared statements for all SQL queries, these positive aspects are overshadowed by critical implementation flaws. The absence of any output escaping on 12 identified output points means that any data processed and displayed by the plugin is susceptible to injection attacks, such as Cross-Site Scripting (XSS). Furthermore, the use of `create_function` is a deprecated and inherently risky practice that can lead to unexpected behavior and potential security loopholes if not handled with extreme care. The lack of any reported CVEs is a positive indicator, but it does not mitigate the immediate risks posed by the static analysis findings. The plugin's attack surface appears limited in terms of entry points, but the identified code signals point to significant vulnerabilities that require immediate attention.

Key Concerns

  • Output escaping is not implemented
  • Use of dangerous function 'create_function'
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Jet Random Members Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Jet Random Members Widget Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
12
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'return register_widget("JetRandomMMetaList");'));j-rnd-members.php:136

Output Escaping

0% escaped12 total outputs
Attack Surface

Jet Random Members Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initj-rnd-members.php:136
Maintenance & Trust

Jet Random Members Widget Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedUnknown
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Jet Random Members Widget Developer Profile

milordk

4 plugins · 40 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Jet Random Members Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jet-member-could/style.css
Version Parameters
jet-member-could/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
avatar-blockitem-avatar
Data Attributes
data-id
FAQ

Frequently Asked Questions about Jet Random Members Widget