SB Random Posts Widget Security & Risk Analysis

wordpress.org/plugins/sb-random-posts-widget

Simple way display random posts in your blogroll

10 active installs v1.1 PHP + WP 3.3+ Updated Oct 11, 2024
postsrandom-postswidget
90
A · Safe
CVEs total1
Unpatched0
Last CVEOct 9, 2024
Safety Verdict

Is SB Random Posts Widget Safe to Use in 2026?

Generally Safe

Score 90/100

SB Random Posts Widget has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Oct 9, 2024Updated 1yr ago
Risk Assessment

The static analysis for sb-random-posts-widget v1.1 indicates a generally strong security posture with several good practices observed. The plugin demonstrates excellent control over its attack surface, with no unprotected AJAX handlers or REST API routes. The overwhelming majority of output is properly escaped, and all SQL queries utilize prepared statements, significantly reducing the risk of SQL injection. The absence of file operations and external HTTP requests further strengthens its security profile.

Despite these positive findings, the plugin's vulnerability history is a significant concern. The presence of one known high-severity vulnerability, specifically a PHP Remote File Inclusion, raises a red flag. While this vulnerability is currently patched according to the data, its nature suggests potential underlying architectural weaknesses that could be exploited if similar flaws are introduced in future versions. The lack of any identified taint flows in the current analysis is reassuring, but the past vulnerability highlights the importance of rigorous code review and secure coding practices.

In conclusion, sb-random-posts-widget v1.1 exhibits good code hygiene in its current state, with minimal immediate risks identified through static analysis. However, the past high-severity vulnerability necessitates vigilance. Users should ensure they are running the latest version of the plugin to mitigate past issues and be aware that the historical vulnerability type could be indicative of areas that require ongoing scrutiny. The plugin's strengths lie in its controlled attack surface and proper data handling, while its primary weakness is its past security incident.

Key Concerns

  • High severity vulnerability historically
  • No nonce checks
  • No capability checks
Vulnerabilities
1 published

SB Random Posts Widget Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-48029high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

SB Random Posts Widget <= 1.0 - Authenticated (Contributor+) Local File Inclusion

Oct 9, 2024 Patched in 1.1 (8d)
Version History

SB Random Posts Widget Release Timeline

v1.1Current
v1.01 CVE
Code Analysis
Analyzed Mar 17, 2026

SB Random Posts Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
74 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped75 total outputs
Attack Surface

SB Random Posts Widget Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[sb_random_posts] sb-random-posts-widget.php:35
WordPress Hooks 2
actionwp_enqueue_scriptsclasses.php:5
actionwidgets_initsb-random-posts-widget.php:41
Maintenance & Trust

SB Random Posts Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 11, 2024
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

SB Random Posts Widget Developer Profile

Hung Trang Si

3 plugins · 410 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect SB Random Posts Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sb-random-posts-widget/assets/style.css

HTML / DOM Fingerprints

CSS Classes
random-postssimple_random_posts
Data Attributes
data-num
Shortcode Output
[sb_random_posts
FAQ

Frequently Asked Questions about SB Random Posts Widget