Random Redirect Security & Risk Analysis

wordpress.org/plugins/random-redirect

Allows you to create a link to yourblog.example.com/?random which will redirect someone to a random post on your blog, in a StumbleUpon-like fashion. You can also specific in the URL `random_post_type` or `random_cat_id`.

200 active installs v1.1 PHP + WP + Updated Aug 4, 2008
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Random Redirect Safe to Use in 2026?

Generally Safe

Score 85/100

Random Redirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 17yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'random-redirect' plugin v1.1 exhibits a strong security posture. The code analysis reveals no dangerous functions, external HTTP requests, file operations, or SQL queries that are not properly prepared. Notably, there are no identified taint flows, indicating that user input is likely handled securely and not being passed to sensitive functions without proper sanitization. The complete absence of known CVEs, both past and present, further reinforces its current security standing.

While the plugin demonstrates good practices in its codebase by avoiding common pitfalls, the complete lack of capability checks or nonce checks on its entry points (even though the attack surface is currently zero) could present a future risk if functionality is added without corresponding security measures. The absence of any recorded vulnerabilities suggests a well-maintained and secure development history. Overall, this plugin appears to be a low-risk component, but vigilance regarding future updates and any expansion of its functionality is advisable.

Vulnerabilities
None known

Random Redirect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Random Redirect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries
Attack Surface

Random Redirect Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actiontemplate_redirectrandom-redirect.php:35
Maintenance & Trust

Random Redirect Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedAug 4, 2008
PHP min version
Downloads24K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Alternatives

Random Redirect Alternatives

No alternatives data available yet.

Developer Profile

Random Redirect Developer Profile

Automattic

393 plugins · 20.8M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
1221 days
View full developer profile
Detection Fingerprints

How We Detect Random Redirect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Random Redirect