
Random Excerpts Fader Security & Risk Analysis
wordpress.org/plugins/random-excerpts-faderCreates a widget that takes randomly a number of excerpts from a category of your choice and fades them in and out.
Is Random Excerpts Fader Safe to Use in 2026?
Generally Safe
Score 85/100Random Excerpts Fader has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'random-excerpts-fader' plugin v2.4.1 exhibits a generally good security posture with a limited attack surface and no known past vulnerabilities. The absence of any recorded CVEs, unpatched vulnerabilities, or common vulnerability types is a strong indicator of a well-maintained and secure codebase. The static analysis also shows promising signs, such as 100% of SQL queries using prepared statements, no file operations, and no external HTTP requests. However, several concerning code signals warrant attention. The presence of the `create_function` dangerous function is a significant risk, as it can lead to arbitrary code execution if user-supplied data is passed to it without proper sanitization. Furthermore, the extremely low percentage of properly escaped outputs (2%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where attackers could inject malicious scripts into the website that are then rendered by users. The lack of nonce checks and capability checks on the identified shortcode, while not explicitly flagged as unprotected, is a potential oversight that could be exploited in conjunction with other vulnerabilities or by a determined attacker.
Key Concerns
- Dangerous function 'create_function' found
- Only 2% of outputs are properly escaped
- No nonce checks on entry points
- No capability checks on entry points
Random Excerpts Fader Security Vulnerabilities
Random Excerpts Fader Code Analysis
Dangerous Functions Found
Output Escaping
Random Excerpts Fader Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Random Excerpts Fader Maintenance & Trust
Maintenance Signals
Community Trust
Random Excerpts Fader Alternatives
Random Content
random-content
Display random content anywhere on your WordPress site. Rotate testimonials, banners, CTAs, and more with a simple shortcode or widget.
BNE Testimonials
bne-testimonials
Display testimonials and reviews on any page or widget area as list or slider. Upgrade to PRO for additional layouts, themes, submission form, API, ra …
Better Random Redirect
better-random-redirect
Based on the original Random Redirect, this plugin enables efficient, easy random redirection to a post. Supports setting a category for all random re …
Easy Quotes
easy-quotes
Collect and show your favorite Quotes / Reviews / Testimonials or any other short snippet of Text.
Advanced Random Posts
advanced-random-posts
Display random posts from selected categories or current category or all posts with thumbnail images (optional).
Random Excerpts Fader Developer Profile
6 plugins · 180 total installs
How We Detect Random Excerpts Fader
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/random-excerpts-fader/js/random-excerpts-fader.js/wp-content/plugins/random-excerpts-fader/css/random-excerpts-fader.css/wp-content/plugins/random-excerpts-fader/js/random-excerpts-fader.jsrandom-excerpts-fader/js/random-excerpts-fader.js?ver=random-excerpts-fader/css/random-excerpts-fader.css?ver=HTML / DOM Fingerprints
reFader_widgetid="reFader-admin-panel"name="reFader_widget"id="reFader_widget"<div class="random-excerpts-fader-wrap"><div class="excerpt"><p></p>