
Comfortable Reading Security & Risk Analysis
wordpress.org/plugins/comfortable-readingВерсия сайта для слабовидящих пользователей.
Is Comfortable Reading Safe to Use in 2026?
Generally Safe
Score 85/100Comfortable Reading has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'comfortable-reading' plugin v1.6.6 presents a mixed security posture. On the positive side, it demonstrates good practices by not making external HTTP requests, performing file operations, or directly executing SQL queries without prepared statements. The absence of known CVEs and a clean vulnerability history are also strong indicators of responsible development. However, significant concerns arise from the static code analysis. The presence of the `create_function` dangerous function is a red flag, as it can be exploited for code injection if user-supplied data is not meticulously sanitized before being passed to it. Furthermore, the extremely low output escaping rate (13%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The lack of nonce and capability checks on the identified shortcode, while it doesn't constitute a direct entry point without authorization in this analysis, is a common oversight that can lead to privilege escalation or unauthorized actions in conjunction with other vulnerabilities.
While the plugin boasts zero direct entry points without authentication and no critical taint flows, the identified code signals present latent risks. The `create_function` usage is a critical vulnerability waiting to be exploited if the data it processes is not extremely well validated. The poor output escaping is a widespread vulnerability that could affect many areas of the plugin's functionality. The vulnerability history shows a complete lack of past issues, which is commendable, but it does not absolve the plugin from the risks identified in the current version's code. The overall assessment is that while the plugin has a clean track record and some good security implementations, the identified code-level weaknesses, particularly `create_function` and output escaping, introduce significant potential for exploitation.
Key Concerns
- Presence of dangerous function create_function
- Low output escaping rate (13%)
- Shortcode without nonce checks
- Shortcode without capability checks
Comfortable Reading Security Vulnerabilities
Comfortable Reading Release Timeline
Comfortable Reading Code Analysis
Dangerous Functions Found
Output Escaping
Comfortable Reading Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Comfortable Reading Maintenance & Trust
Maintenance Signals
Community Trust
Comfortable Reading Alternatives
Global Styles Mods – WordPress 5.9 fix
global-styles-mods
Fixes styling issues in WordPress 5.9 modifying global styles code.
Font Resize With Post Reading Time [GWE]
font-resizer-with-post-reading-time
With this plugin, you can easily display post reading time and a font resizing option on every single blog page.
Barrierefrei Helper
barrierefrei-helper
Verbessert die Barrierefreiheit auf Websites mit Anpassungen wie Schriftgrößenänderung, Farbwahl, und Kontrastmodus.
Change font size and color
change-font-size-and-color
Change font style by changing its size and colors for entire website.
SiteEase Accessibility Pro
site-accessibility
SiteEase Accessibility Pro improves website readability and usability by allowing users to adjust font size, colors, and other visual settings.
Comfortable Reading Developer Profile
2 plugins · 1K total installs
How We Detect Comfortable Reading
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comfortable-reading/css/custom.css/wp-content/plugins/comfortable-reading/js/jquery.comfortable.reading.js/wp-content/plugins/comfortable-reading/js/jquery.cookie.js/wp-content/plugins/comfortable-reading/js/jquery.comfortable.reading.js/wp-content/plugins/comfortable-reading/js/jquery.cookie.jscomfortable-reading/css/custom.css?ver=comfortable-reading/js/jquery.comfortable.reading.js?ver=comfortable-reading/js/jquery.cookie.js?ver=HTML / DOM Fingerprints
cr-descriptioncr-ul-styleid="cr_version_link"id="cr_widget"<a href="#" id="cr_version_link">