Random Posts from Category Security & Risk Analysis

wordpress.org/plugins/random-posts-from-category

A widget that lists random posts from a chosen category.

200 active installs v1.30 PHP + WP 2.8+ Updated Apr 22, 2016
postsrandomwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Random Posts from Category Safe to Use in 2026?

Generally Safe

Score 85/100

Random Posts from Category has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "random-posts-from-category" plugin v1.30 exhibits a strong security posture based on the provided static analysis. The complete absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code analysis reveals no dangerous function usage, file operations, or external HTTP requests. The fact that all SQL queries utilize prepared statements is a critical good practice. However, a notable concern is the low percentage of properly escaped output (24%). This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled securely before being displayed to the user. The plugin's vulnerability history is also clean, with no known CVEs recorded, which is a positive indicator of its current security. While the lack of entry points and adherence to secure SQL practices are commendable, the insufficient output escaping presents a tangible risk that should be addressed to achieve a truly robust security profile.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

Random Posts from Category Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Random Posts from Category Release Timeline

v1.30Current
v1.16
v1.15
v1.14
v1.13
v1.12
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Random Posts from Category Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

24% escaped33 total outputs
Attack Surface

Random Posts from Category Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initrandom-from-category-widget.php:148
Maintenance & Trust

Random Posts from Category Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 22, 2016
PHP min version
Downloads19K

Community Trust

Rating80/100
Number of ratings2
Active installs200
Developer Profile

Random Posts from Category Developer Profile

Stephanie Leary

16 plugins · 17K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
2856 days
View full developer profile
Detection Fingerprints

How We Detect Random Posts from Category

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/random-posts-from-category/random-posts-from-category.php
Version Parameters
random-posts-from-category/random-posts-from-category.php?ver=random-posts-from-category.php?ver=

HTML / DOM Fingerprints

CSS Classes
random_from_cat
Data Attributes
id="random-posts-from-category-title"name="random-posts-from-category-title"id="random-posts-from-category-cat"name="random-posts-from-category-cat"id="random-posts-from-category-showposts"name="random-posts-from-category-showposts"+8 more
FAQ

Frequently Asked Questions about Random Posts from Category