
Random Related Posts Security & Risk Analysis
wordpress.org/plugins/random-related-postsA simple sidebar widget to include a custom number of posts from the same category as the current post.
Is Random Related Posts Safe to Use in 2026?
Generally Safe
Score 85/100Random Related Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'random-related-posts' v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin has no known vulnerabilities (CVEs) and its SQL queries are exclusively handled with prepared statements, which is a strong security practice. Furthermore, the static analysis reveals a very small attack surface with no discoverable AJAX handlers, REST API routes, shortcodes, or cron events, and crucially, none of these potential entry points appear to be unprotected.
However, significant concerns arise from the code signals. The presence of the `create_function` is a critical security risk, as it can be exploited for arbitrary code execution. Additionally, only 13% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce and capability checks, while seemingly mitigated by the limited attack surface, leaves potential for privilege escalation or unauthorized actions if any vulnerabilities are ever introduced through code modification or future updates.
Given the lack of historical vulnerabilities, it's difficult to draw definitive conclusions about long-term maintenance. However, the current code analysis highlights serious flaws that outweigh the limited attack surface. The use of `create_function` and the high percentage of unescaped output are immediate and severe risks that require urgent attention. While the absence of a large attack surface is a strength, it does not mitigate the inherent dangers within the existing code.
Key Concerns
- Use of create_function
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Random Related Posts Security Vulnerabilities
Random Related Posts Code Analysis
Dangerous Functions Found
Output Escaping
Random Related Posts Attack Surface
WordPress Hooks 1
Maintenance & Trust
Random Related Posts Maintenance & Trust
Maintenance Signals
Community Trust
Random Related Posts Alternatives
Advanced Random Posts Widget
advanced-random-posts-widget
Provides flexible and advanced random posts. Display it via shortcode or widget with thumbnails, post excerpt, and much more!
Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager
custom-sidebars
Flexible sidebars for custom classic widget configurations on any page or post. Create custom sidebars with ease!
Image Widget
image-widget
A simple image widget that uses the native WordPress media manager to add image widgets to your site.
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
WooSidebars
woosidebars
WooSidebars adds functionality to display different widgets in a sidebar, according to a context (for example, a specific page or a category).
Random Related Posts Developer Profile
6 plugins · 400 total installs
How We Detect Random Related Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/random-related-posts/style.cssrandom-related-posts/style.css?ver=HTML / DOM Fingerprints
related-titlerandom-postsbydaterelated-posts