Random Look Security & Risk Analysis

wordpress.org/plugins/random-look

添加随便看看,顾名思义就是随机给出文章来看看,很小但很实用。

10 active installs v1.0.1 PHP 5.6.0+ WP 4.6+ Updated Dec 5, 2025
%e9%9a%8f%e6%9c%ba%e9%9a%8f%e4%be%bf%e7%9c%8b%e7%9c%8brandom
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Random Look Safe to Use in 2026?

Generally Safe

Score 100/100

Random Look has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "random-look" v1.0.1 plugin exhibits a very strong security posture based on the provided static analysis. The absence of any detected attack surface, including AJAX handlers, REST API routes, shortcodes, or cron events, significantly limits potential entry points for malicious actors. Furthermore, the code analysis reveals no dangerous functions, no unsanitized taint flows, and SQL queries are exclusively handled with prepared statements. The presence of a capability check further adds to the security, indicating an awareness of access control. The plugin's vulnerability history is also clean, with no known CVEs recorded. This indicates a mature and secure development approach. However, the lack of nonce checks, while not immediately concerning given the zero attack surface, is a common security best practice that is absent. Similarly, while most output is escaped, the 20% that is not could theoretically pose a risk if certain conditions were met, although the lack of any defined attack vectors makes this highly improbable. Overall, this plugin appears to be very secure.

Key Concerns

  • Missing nonce checks
  • Unescaped output (20% of total)
Vulnerabilities
None known

Random Look Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Random Look Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Random Look Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
1
4 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

80% escaped5 total outputs
Attack Surface

Random Look Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menurandom-look.php:27
filterplugin_action_linksrandom-look.php:36
actioninitrandom-look.php:41
actiontemplate_redirectrandom-look.php:45
Maintenance & Trust

Random Look Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 5, 2025
PHP min version5.6.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Random Look Developer Profile

沈唁

14 plugins · 4K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
143 days
View full developer profile
Detection Fingerprints

How We Detect Random Look

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Random Look