
Llama Shuffle — by Barking Llama Security & Risk Analysis
wordpress.org/plugins/llama-shuffle-by-barking-llamaThe Loose Llama Randomizer. Serve a random image from Media Library image sets or a URL list via a portable endpoint or REST API.
Is Llama Shuffle — by Barking Llama Safe to Use in 2026?
Generally Safe
Score 100/100Llama Shuffle — by Barking Llama has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "llama-shuffle-by-barking-llama" plugin version 1.0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history is a significant positive indicator. The code demonstrates good practices, including the use of prepared statements for all SQL queries, robust output escaping with only a minimal percentage of unescaped outputs, and the presence of nonce and capability checks, suggesting an effort to protect against common web vulnerabilities. The attack surface appears minimal, with only one shortcode identified and no unprotected entry points in AJAX handlers or REST API routes.
However, the static analysis report indicates zero taint flows analyzed. While this might mean no exploitable flows were found, it also suggests that a comprehensive taint analysis may not have been performed, leaving potential blind spots. The low number of entry points (1) is positive, but the presence of even one shortcode warrants careful consideration. Without specific details on the shortcode's functionality, it's difficult to definitively rule out potential risks related to user-supplied input within that shortcode, despite the overall good escaping and auth checks.
In conclusion, the plugin appears to be developed with security in mind, demonstrating good fundamental security practices. The lack of historical vulnerabilities and the positive static analysis findings provide a good degree of confidence. The primary area for potential improvement, or at least further investigation, would be a more thorough taint analysis to ensure no edge cases or complex data flows have been overlooked. The current risk is assessed as low.
Llama Shuffle — by Barking Llama Security Vulnerabilities
Llama Shuffle — by Barking Llama Code Analysis
Output Escaping
Llama Shuffle — by Barking Llama Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Llama Shuffle — by Barking Llama Maintenance & Trust
Maintenance Signals
Community Trust
Llama Shuffle — by Barking Llama Alternatives
Image Roulette – Random Image Block
image-roulette
Display a random image from your Media Library galleries with full accessibility support. Spin the wheel of images!
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
Media Cleaner: Clean your WordPress!
media-cleaner
Clean your WordPress! Eliminate unused and broken media files. For a faster, and better website.
Media Library Assistant
media-library-assistant
Enhances the Media Library; powerful gallery and list shortcodes, full taxonomy support, IPTC/EXIF/XMP/PDF processing, bulk/quick edit.
Crop-Thumbnails
crop-thumbnails
"Crop Thumbnails" made it easy to get exacly that specific image-detail you want to show in your featured image or gallery image.
Llama Shuffle — by Barking Llama Developer Profile
2 plugins · 0 total installs
How We Detect Llama Shuffle — by Barking Llama
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/llama-shuffle-by-barking-llama/css/llama-shuffle-admin.css/wp-content/plugins/llama-shuffle-by-barking-llama/css/llama-shuffle-frontend.css/wp-content/plugins/llama-shuffle-by-barking-llama/js/llama-shuffle-admin.js/wp-content/plugins/llama-shuffle-by-barking-llama/js/llama-shuffle-frontend.js/wp-content/plugins/llama-shuffle-by-barking-llama/js/llama-shuffle-admin.js/wp-content/plugins/llama-shuffle-by-barking-llama/js/llama-shuffle-frontend.js/wp-content/plugins/llama-shuffle-by-barking-llama/css/llama-shuffle-admin.css?ver=/wp-content/plugins/llama-shuffle-by-barking-llama/css/llama-shuffle-frontend.css?ver=/wp-content/plugins/llama-shuffle-by-barking-llama/js/llama-shuffle-admin.js?ver=/wp-content/plugins/llama-shuffle-by-barking-llama/js/llama-shuffle-frontend.js?ver=HTML / DOM Fingerprints
llama-shuffle-wrapperllama-shuffle-image<!-- Llama Shuffle Shortcode -->data-llama-shuffle-optionsllamaShuffleFrontendConfig/wp-json/llama-shuffle/v1/shuffle<div class="llama-shuffle-wrapper"><img class="llama-shuffle-image" src="" alt=""></div>