
Article Read Time Security & Risk Analysis
wordpress.org/plugins/article-read-timeDisplays estimated article reading time using shortcode or template tag with customizable formats.
Is Article Read Time Safe to Use in 2026?
Generally Safe
Score 100/100Article Read Time has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "article-read-time" v1.0 plugin exhibits a strong security posture based on the provided static analysis. All identified entry points, including the single shortcode, are either explicitly protected or have no authentication checks required, implying minimal risk from direct attack vectors. The code demonstrates excellent security practices by utilizing prepared statements for all SQL queries and properly escaping all output, eliminating common vulnerabilities related to data injection and cross-site scripting. The absence of file operations, external HTTP requests, and bundled libraries further reduces the potential attack surface. The plugin's vulnerability history is also clean, with no recorded CVEs, suggesting a history of secure development or diligent patching if any issues did arise in the past. The lack of taint analysis results with vulnerabilities also contributes to the positive security assessment.
However, it's important to note a few areas for caution. The plugin does not implement any nonce checks or capability checks. While the current entry points might not directly require these, the absence of these fundamental WordPress security mechanisms could become a concern if the plugin's functionality evolves or if any new entry points are introduced in future versions without proper authorization checks. The lack of nonce checks, in particular, can leave even seemingly innocuous functionalities vulnerable to CSRF attacks if they perform any actions on the server-side. Despite these minor points, the overall security of this version appears robust due to the adherence to core secure coding principles.
Key Concerns
- Missing nonce checks
- Missing capability checks
Article Read Time Security Vulnerabilities
Article Read Time Code Analysis
Output Escaping
Article Read Time Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Article Read Time Maintenance & Trust
Maintenance Signals
Community Trust
Article Read Time Alternatives
Font Resize With Post Reading Time [GWE]
font-resizer-with-post-reading-time
With this plugin, you can easily display post reading time and a font resizing option on every single blog page.
Sam Reading Time
sam-reading-time
Display estimated reading time for your posts using a clean shortcode. Includes a lightweight settings panel under the "Posts" menu.
My Post Time
my-post-time
My Post Time plugin is an innovative and useful plugin that is designed to help your readers more efficiently read your blog posts.
Simple Reading Time
simple-reading-time
This plugin scans your article and generates average reading time, number of words divided by 200.
Ultimate Reading Time
ultimate-reading-time
Ultimate solution for displaying reading time on your posts and pages.
Article Read Time Developer Profile
5 plugins · 350 total installs
How We Detect Article Read Time
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
article-read-time<span class="article-read-time">