# jetpack/16.2/modules/theme-tools/random-redirect.php

Jetpack – WP Security, Backup, Speed, &amp; Growth, version 16.2. 139 lines.

- Page: https://pluginprobe.com/plugins/jetpack/16.2/code/modules/theme-tools/random-redirect.php
- Raw: https://pluginprobe.com/plugins/jetpack/16.2/raw/modules/theme-tools/random-redirect.php
- Modified: 2026-08-04T22:02:04+00:00

Line numbers below start at 1. Link to a line or a range by appending a fragment to the
page URL, for example `https://pluginprobe.com/plugins/jetpack/16.2/code/modules/theme-tools/random-redirect.php#L10-L20`.

```php
<?php
/**
 * Plugin Name: Random Redirect
 * Plugin URI: https://wordpress.org/extend/plugins/random-redirect/
 * Description: Allows you to create a link to yourblog.example.com/?random which will redirect someone to a random post on your blog, in a StumbleUpon-like fashion.
 * Version: 1.2-wpcom
 * Author: Matt Mullenweg
 * Author URI: https://ma.tt/
 * Text Domain: jetpack
 *
 * @package automattic/jetpack
 */

// phpcs:disable WordPress.Security.NonceVerification -- No changes to the site here, it just redirects.

/*
 * This module was removed from the plugin in 13.6 and restored in 16.1. In the meantime some themes
 * and plugins started shipping their own copy of the function below, so only declare it when nothing
 * else has, to avoid a fatal error. The declaration must stay inside this conditional: PHP binds
 * unconditional top-level function declarations when the file is compiled, before any check could run.
 */
if ( ! function_exists( 'jetpack_matt_random_redirect' ) ) {
	/**
	 * Redirects to a random post on the site.
	 */
	function jetpack_matt_random_redirect() {
		/**
		 * Allows disabling the random redirect feature.
		 *
		 * @since 16.1
		 *
		 * @param bool $enabled Whether the random redirect feature is enabled. Default true.
		 */
		if ( ! apply_filters( 'jetpack_random_redirect_enabled', true ) ) {
			return;
		}

		// Verify that the Random Redirect plugin this code is from is not active
		// See https://plugins.trac.wordpress.org/ticket/1898
		if ( ! ( defined( 'IS_WPCOM' ) && IS_WPCOM ) ) {
			require_once ABSPATH . 'wp-admin/includes/plugin.php';
			if ( is_plugin_active( 'random-redirect/random-redirect.php' ) ) {
				return;
			}
		}

		// Acceptable URL formats: /[...]/?random=[post type], /?random, /&random, /&random=1
		if ( ! isset( $_GET['random'] ) && ! ( isset( $_SERVER['REQUEST_URI'] ) && in_array( strtolower( $_SERVER['REQUEST_URI'] ), array( '/&random', '/&random=1' ), true ) ) ) {
			return;
		}

		// Ignore POST requests.
		if ( ! empty( $_POST ) ) {
			return;
		}

		// Persistent AppEngine abuse.  ORDER BY RAND is expensive.
		if ( isset( $_SERVER['HTTP_USER_AGENT'] ) && strstr( filter_var( wp_unslash( $_SERVER['HTTP_USER_AGENT'] ) ), 'AppEngine-Google' ) ) {
			wp_die( 'Please <a href="https://en.support.wordpress.com/contact/" rel="noopener noreferrer" target="_blank">contact support</a>' );
		}

		$where      = array(
			"post_password = ''",
			"post_status = 'publish'",
		);
		$where_args = array();

		// Set default post type.
		$post_type = get_post_type();

		// Change the post type if the parameter is set.
		if ( isset( $_GET['random_post_type'] ) && post_type_exists( sanitize_key( $_GET['random_post_type'] ) ) ) {
			$post_type = sanitize_key( $_GET['random_post_type'] );
		}

		// Don't show a random page if 'page' isn't specified as the post type specifically.
		if ( 'page' === $post_type && is_front_page() && ! isset( $_GET['random_post_type'] ) ) {
			$post_type = 'post';
		}

		$where[]      = 'p.post_type = %s';
		$where_args[] = $post_type;

		// Set author name if we're on an author archive.
		if ( is_author() ) {
			$where[]      = 'post_author = %s';
			$where_args[] = get_the_author_meta( 'ID' );
		}

		// Set default category type
		if ( is_category() ) {
			$category = get_the_category();
			if ( isset( $category ) && ! empty( $category ) ) {
				$random_cat_id = $category[0]->term_id;
			}
		}

		// Set the category ID if the parameter is set.
		if ( isset( $_GET['random_cat_id'] ) ) {
			$random_cat_id = (int) $_GET['random_cat_id'];
		}

		global $wpdb;

		$where = implode( ' AND ', $where );

		// Pick a post via COUNT plus a random OFFSET rather than ORDER BY RAND(), which randomizes and sorts every candidate row on each request.
		if ( isset( $random_cat_id ) ) {
			$from_where = "FROM $wpdb->posts AS p INNER JOIN $wpdb->term_relationships AS tr ON (p.ID = tr.object_id AND tr.term_taxonomy_id = %s) INNER JOIN  $wpdb->term_taxonomy AS tt ON(tr.term_taxonomy_id = tt.term_taxonomy_id AND taxonomy = 'category') WHERE $where";
			$query_args = array_merge( array( $random_cat_id ), $where_args );
		} else {
			$from_where = "FROM $wpdb->posts AS p WHERE $where";
			$query_args = $where_args;
		}

		// phpcs:ignore WordPress.DB.DirectDatabaseQuery, WordPress.DB.PreparedSQL.InterpolatedNotPrepared, WordPress.DB.PreparedSQLPlaceholders.ReplacementsWrongNumber, WordPress.DB.PreparedSQLPlaceholders.UnfinishedPrepare
		$post_count = (int) $wpdb->get_var( $wpdb->prepare( "SELECT COUNT( DISTINCT p.ID ) $from_where", ...$query_args ) );

		if ( $post_count < 1 ) {
			return;
		}

		$query_args[] = wp_rand( 0, $post_count - 1 );
		// phpcs:ignore WordPress.DB.DirectDatabaseQuery, WordPress.DB.PreparedSQL.InterpolatedNotPrepared, WordPress.DB.PreparedSQLPlaceholders.ReplacementsWrongNumber, WordPress.DB.PreparedSQLPlaceholders.UnfinishedPrepare
		$random_id = $wpdb->get_var( $wpdb->prepare( "SELECT DISTINCT p.ID $from_where ORDER BY p.ID LIMIT 1 OFFSET %d", ...$query_args ) );

		if ( ! $random_id ) {
			return;
		}

		// @phan-suppress-next-line PhanTypeMismatchArgument
		$permalink = get_permalink( $random_id );
		wp_safe_redirect( $permalink );
		exit( 0 );
	}

	add_action( 'template_redirect', 'jetpack_matt_random_redirect' );
}

```
