
Jet Random Members Widget Security & Risk Analysis
wordpress.org/plugins/jet-member-coulden: Create a cloud of users on your social network! Do you have many users? Do you want more communication? Install this widget!
Is Jet Random Members Widget Safe to Use in 2026?
Generally Safe
Score 100/100Jet Random Members Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "jet-member-could" v1.3 plugin exhibits a concerning security posture primarily due to its lack of output escaping and the presence of a dangerous function. While the plugin has no recorded vulnerabilities and utilizes prepared statements for all SQL queries, these positive aspects are overshadowed by critical implementation flaws. The absence of any output escaping on 12 identified output points means that any data processed and displayed by the plugin is susceptible to injection attacks, such as Cross-Site Scripting (XSS). Furthermore, the use of `create_function` is a deprecated and inherently risky practice that can lead to unexpected behavior and potential security loopholes if not handled with extreme care. The lack of any reported CVEs is a positive indicator, but it does not mitigate the immediate risks posed by the static analysis findings. The plugin's attack surface appears limited in terms of entry points, but the identified code signals point to significant vulnerabilities that require immediate attention.
Key Concerns
- Output escaping is not implemented
- Use of dangerous function 'create_function'
- No nonce checks on entry points
- No capability checks on entry points
Jet Random Members Widget Security Vulnerabilities
Jet Random Members Widget Code Analysis
Dangerous Functions Found
Output Escaping
Jet Random Members Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Jet Random Members Widget Maintenance & Trust
Maintenance Signals
Community Trust
Jet Random Members Widget Alternatives
Wbcom Designs – Birthday Widget for BuddyPress
birthday-widget-for-buddypress
Display upcoming birthdays of BuddyPress members with a beautiful, responsive widget that integrates seamlessly with any WordPress theme.
BuddyPress Extend Widgets
bp-extend-widgets
Provide all widgets with BuddyPress specific fields (conditional display logic)
Enhanced BuddyPress Widgets
enhanced-buddypress-widgets
Provides enhanced version of BuddyPress's core Groups and Members widgets
Jet Site Unit Could Widgets
jet-unit-site-could
Provides random members and/or groups avatar list + blog list with more options /Widget/
Ocean Extra
ocean-extra
Ocean Extra adds extra features and flexibility to the OceanWP theme for a turbocharged experience.
Jet Random Members Widget Developer Profile
4 plugins · 40 total installs
How We Detect Jet Random Members Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jet-member-could/style.cssjet-member-could/style.css?ver=HTML / DOM Fingerprints
avatar-blockitem-avatardata-id