
Random numbers – WordPress Random numbers builder plugin Security & Risk Analysis
wordpress.org/plugins/random-numbers-builderRandom numbers builder plugin allows the visitor to create random numbers on the page.
Is Random numbers – WordPress Random numbers builder plugin Safe to Use in 2026?
Generally Safe
Score 85/100Random numbers – WordPress Random numbers builder plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'random-numbers-builder' plugin v1.1.6 demonstrates a generally good security posture with several key strengths. The complete absence of known CVEs and a clean vulnerability history are significant positive indicators. The code analysis reveals a small attack surface with no unprotected entry points detected, a strong adherence to using nonces and capability checks, and a lack of dangerous functions or file operations. This suggests a developer who is mindful of common WordPress security pitfalls.
However, there are areas for improvement. While not critical, the SQL queries show only 50% usage of prepared statements, leaving room for potential SQL injection vulnerabilities if the inputs are not meticulously sanitized on the PHP side. Furthermore, only 64% of output escaping is properly implemented. This means a portion of the plugin's output could be susceptible to Cross-Site Scripting (XSS) attacks. The taint analysis showing zero flows is excellent, but the limited output escaping and less-than-perfect SQL preparation mean that these potential weaknesses, if exploited through other means, could still lead to an issue.
In conclusion, 'random-numbers-builder' v1.1.6 is a relatively secure plugin, particularly due to its lack of historical vulnerabilities and protected attack surface. The developer has implemented core security measures like nonce and capability checks effectively. The primary risks lie in the partial implementation of prepared statements for SQL queries and incomplete output escaping, which, while not exploited in the past or detected through taint analysis, represent potential avenues for future exploitation. Addressing these areas would further bolster the plugin's security.
Key Concerns
- SQL queries not fully using prepared statements
- Output escaping not fully implemented
Random numbers – WordPress Random numbers builder plugin Security Vulnerabilities
Random numbers – WordPress Random numbers builder plugin Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Random numbers – WordPress Random numbers builder plugin Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Random numbers – WordPress Random numbers builder plugin Maintenance & Trust
Maintenance Signals
Community Trust
Random numbers – WordPress Random numbers builder plugin Alternatives
Random Number Generator
random-number-generator
Simply replace the tag [random-number] by a random number.
WP Call Button – Easy Click to Call Button for WordPress
wp-call-button
The best WordPress call now button plugin. We help you add a clickable phone link (quick call button), so people can easily call your business phone.
Sequential Order Number for WooCommerce
wt-woocommerce-sequential-order-numbers
Sequential order number for WooCommerce is the best plugin to generate sequential or custom order numbers for existing and new WooCommerce orders.
Custom Order Numbers for WooCommerce
custom-order-numbers-for-woocommerce
Set Sequential order numbers in WooCommerce. Custom order number with prefixes can also be set for existing and new WooCommerce orders.
Quick Adsense
quick-adsense
Quick Adsense offers a quicker & flexible way to insert Google Adsense or any Ads code into a blog post.
Random numbers – WordPress Random numbers builder plugin Developer Profile
2 plugins · 10K total installs
How We Detect Random numbers – WordPress Random numbers builder plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/random-numbers-builder/css/YrnCountUp.css/wp-content/plugins/random-numbers-builder/js/YrnCountUp.js/wp-content/plugins/random-numbers-builder/css/rn-builder.css/wp-content/plugins/random-numbers-builder/css/rn-builder-editor.css/wp-content/plugins/random-numbers-builder/js/rn-builder.js/wp-content/plugins/random-numbers-builder/js/rn-builder-editor.js/wp-content/plugins/random-numbers-builder/js/YrnCountUp.js/wp-content/plugins/random-numbers-builder/js/rn-builder.js/wp-content/plugins/random-numbers-builder/js/rn-builder-editor.jsrandom-numbers-builder/css/YrnCountUp.css?ver=random-numbers-builder/js/YrnCountUp.js?ver=random-numbers-builder/css/rn-builder.css?ver=random-numbers-builder/css/rn-builder-editor.css?ver=random-numbers-builder/js/rn-builder.js?ver=random-numbers-builder/js/rn-builder-editor.js?ver=HTML / DOM Fingerprints
YRN-contentYRN-content-wrapper-YRN-content-htmldata-stylesdata-iddata-optionsYRN_VERSIONYRN_CSS_URLYRN_JS_URL[yrn_numbers