
rng-isuc Security & Risk Analysis
wordpress.org/plugins/rng-isucWordPress Plugin that shows the last post viewed by a user in several template views like widget, shortcode and sidebar navigation isuc is standing fo …
Is rng-isuc Safe to Use in 2026?
Generally Safe
Score 85/100rng-isuc has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rng-isuc" v1.0 plugin demonstrates a mixed security posture. On the positive side, it shows good practices by exclusively using prepared statements for SQL queries and implementing nonce and capability checks on its entry points. The lack of known CVEs and a history of vulnerabilities suggests a generally stable and likely well-maintained codebase, at least in terms of publicly disclosed issues. However, there are significant areas of concern.
The static analysis reveals a critical risk associated with the use of the `unserialize()` function, which is a known vector for remote code execution vulnerabilities if not handled with extreme care. Compounding this, the taint analysis indicates one flow with an unsanitized path, specifically identified as having high severity. This, combined with a concerningly low rate of proper output escaping (43%), means that data processed by the plugin could potentially be manipulated and lead to cross-site scripting (XSS) or other injection attacks.
While the plugin has a small attack surface and no directly unprotected entry points, the presence of `unserialize()` and the high-severity unsanitized taint flow are significant weaknesses that require immediate attention. The absence of historical vulnerabilities is a positive indicator, but it does not negate the risks identified in the current code analysis. Developers should prioritize addressing the identified taint flow and securely handling any data passed to `unserialize()`.
Key Concerns
- Dangerous function unserialize() used
- Taint analysis: 1 high severity unsanitized path
- Output escaping: only 43% properly escaped
rng-isuc Security Vulnerabilities
rng-isuc Release Timeline
rng-isuc Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
rng-isuc Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
rng-isuc Maintenance & Trust
Maintenance Signals
Community Trust
rng-isuc Alternatives
rng-postviews
rng-postviews
WordPress plugin that set post view count for each post and reports them in a chart.
A Random Number
a-random-number
A WordPress plugin that displays a random number on each page load via shortcode. It truly is magic.
rng-ajaxlike
rng-ajaxlike
rng-ajaxlike allow the visitor to like posts content on a single page using Ajax technology.
rng-shrotlink
rng-shortlink
rng-shortlink creates a short link for posts and any post types you want and shows reports from clicking count in the admin panel.
rng-isuc Developer Profile
4 plugins · 40 total installs
How We Detect rng-isuc
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rng-isuc/public/js/uc-last-post-viewed.js/wp-content/plugins/rng-isuc/public/js/uc-last-post-viewed-sidenav.js/wp-content/plugins/rng-isuc/public/css/uc-last-post-viewed.css/wp-content/plugins/rng-isuc/public/js/uc-last-post-viewed.js/wp-content/plugins/rng-isuc/public/js/uc-last-post-viewed-sidenav.jsrng-isuc/public/js/uc-last-post-viewed.js?ver=rng-isuc/public/js/uc-last-post-viewed-sidenav.js?ver=rng-isuc/public/css/uc-last-post-viewed.css?ver=HTML / DOM Fingerprints
uc-posts-viewed-widgetuc-posts-viewed-shortcodeuc-posts-viewed-sidenav<!-- rng-isuc plugin templates start --><!-- rng-isuc plugin templates end -->data-rnguc-settingdata-rnguc-post-idwindow.uc_ajax_object[isuc_posts_viewed]