Random Gallery Security & Risk Analysis

wordpress.org/plugins/random-gallery

Random Gallery displays a different subset of your images every time your page is refreshed.

200 active installs v00.08 PHP + WP 3.0.1+ Updated Apr 2, 2023
categorygalleryimagesrandomsubset
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Random Gallery Safe to Use in 2026?

Generally Safe

Score 85/100

Random Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "random-gallery" plugin, version v00.08, exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, SQL injection risks through prepared statements, and properly escaped output are significant strengths. The plugin also demonstrates robust protection for its attack surface, with all identified entry points (the single shortcode) lacking explicit authorization checks, which could be a point of concern if the shortcode handles sensitive operations or user-specific data. However, without a defined capability check or nonce verification for this shortcode, there's a theoretical risk of unauthorized access or manipulation if its functionality permits it. The plugin's history is completely clean, with no recorded CVEs of any severity, indicating a track record of secure development. While the lack of explicit authorization checks on the shortcode is a minor concern, the overall picture is one of a well-developed and secure plugin. The absence of any identified taint flows or critical vulnerabilities further reinforces this assessment.

Key Concerns

  • Shortcode without capability check
Vulnerabilities
None known

Random Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Random Gallery Release Timeline

v00.01
Code Analysis
Analyzed Mar 16, 2026

Random Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Random Gallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[random-gallery] random-gallery.php:86
Maintenance & Trust

Random Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 2, 2023
PHP min version
Downloads7K

Community Trust

Rating90/100
Number of ratings11
Active installs200
Developer Profile

Random Gallery Developer Profile

David G

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Random Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
[gallery
FAQ

Frequently Asked Questions about Random Gallery