
Show Random Products Security & Risk Analysis
wordpress.org/plugins/show-random-productsA widget + shortcode to show random products in your store
Is Show Random Products Safe to Use in 2026?
Generally Safe
Score 100/100Show Random Products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'show-random-products' plugin v1.0.0 presents a mixed security posture. On the positive side, it demonstrates a strong commitment to secure SQL practices by utilizing prepared statements for all its queries and has a clean vulnerability history with no known CVEs. The attack surface is also relatively small, with only one shortcode identified as an entry point, and no unprotected AJAX handlers or REST API routes. However, significant concerns arise from the code signals. The use of `create_function` is a critical security risk as it can lead to remote code execution if exploited. Furthermore, the complete lack of output escaping for all identified outputs means that any dynamic data displayed by the plugin is highly susceptible to cross-site scripting (XSS) attacks. The absence of nonce checks and capability checks, while not directly tied to entry points in this version, leaves the plugin vulnerable to privilege escalation or unauthorized actions if new entry points were introduced or existing ones modified without proper checks.
In conclusion, while the plugin avoids common pitfalls like unpatched vulnerabilities and raw SQL, the identified use of `create_function` and the pervasive lack of output escaping are severe security weaknesses. These issues significantly undermine the plugin's overall security, making it a high risk for deployment without immediate remediation. The absence of known vulnerabilities in its history might indicate a lack of rigorous security auditing or a limited scope of use, but it does not negate the demonstrable risks present in the current codebase.
Key Concerns
- Use of create_function
- No output escaping
- No nonce checks
- No capability checks
Show Random Products Security Vulnerabilities
Show Random Products Code Analysis
Dangerous Functions Found
Output Escaping
Show Random Products Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Show Random Products Maintenance & Trust
Maintenance Signals
Community Trust
Show Random Products Alternatives
Kaya QR Code Generator
kaya-qr-code-generator
Generate QR Code through Widgets and Shortcodes, without any dependencies.
YITH WooCommerce Product Slider Carousel
yith-woocommerce-product-slider-carousel
YITH WooCommerce Product Slider Carousel allows you to create responsive product sliders!
Related Products for WooCommerce
woo-related-products-refresh-on-reload
Display random related products in a slider based on product category, tag, or attribute on every product page.
Product Filter Widget for Elementor
product-filter-widget-for-elementor
Product Filter Widget for Elementor Lets you give functionality to filter your products.
Unyson WooComerce Shortcodes
uws-unyson-woocommerce-shortcodes
A simple and easy way to use WooCommerce Shortcodes in Unyson Visual Builder
Show Random Products Developer Profile
4 plugins · 60 total installs
How We Detect Show Random Products
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/show-random-products/assets/css/main.cssshow-random-products/assets/css/main.css?ver=1.0.0HTML / DOM Fingerprints
srp_widget_randomid="srp_widget_random"name="srp_widget_random[]"id="srp_random"name="srp_random[]"[srp_random]