
My Post Time Security & Risk Analysis
wordpress.org/plugins/my-post-timeMy Post Time plugin is an innovative and useful plugin that is designed to help your readers more efficiently read your blog posts.
Is My Post Time Safe to Use in 2026?
Generally Safe
Score 85/100My Post Time has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "my-post-time" v1.0.0 plugin exhibits a generally positive security posture, with no reported vulnerabilities (CVEs) or critical findings in taint analysis. The absence of dangerous functions, file operations, and external HTTP requests are strong indicators of good development practices. The plugin also demonstrates a commitment to secure database interactions, as all SQL queries utilize prepared statements. Furthermore, the attack surface is limited, with no unprotected AJAX handlers or REST API routes, and a single capability check adds a layer of access control.
However, a significant concern arises from the low percentage of properly escaped output (9%). This indicates that a substantial portion of data being displayed to users may not be adequately sanitized, leaving the plugin vulnerable to cross-site scripting (XSS) attacks. The lack of nonce checks, while not directly linked to an unprotected entry point in this analysis, is a missed opportunity for defense-in-depth and could become a liability if new entry points are introduced or existing ones are inadvertently exposed. The absence of taint flows analyzed could mean either no flows exist or the analysis tools were not configured to detect them, which is a minor weakness in comprehensive security review.
In conclusion, while the plugin is built on a foundation of secure practices and benefits from a clean vulnerability history, the unescaped output presents a clear and present risk. Addressing the output escaping issue should be the highest priority. The lack of nonce checks should also be reviewed for potential improvement.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks on entry points
My Post Time Security Vulnerabilities
My Post Time Code Analysis
Output Escaping
My Post Time Attack Surface
Shortcodes 2
WordPress Hooks 11
Maintenance & Trust
My Post Time Maintenance & Trust
Maintenance Signals
Community Trust
My Post Time Alternatives
Reading Position Indicator
reading-position-indicator
Add reading position indicator on page top.
Font Resize With Post Reading Time [GWE]
font-resizer-with-post-reading-time
With this plugin, you can easily display post reading time and a font resizing option on every single blog page.
Article Read Time Lite – WordPress plugin for displaying total reading time and progress bar
article-read-time-lite
Calculate and display total reading time| Calculate and display Characters and Words | Progress Bar
Article Read Time
article-read-time
Displays estimated article reading time using shortcode or template tag with customizable formats.
Reading Progress Bar
blog-reading-progress-bar
A modern WordPress plugin that adds a customizable reading progress bar to your blog posts with advanced styling options.
My Post Time Developer Profile
1 plugin · 0 total installs
How We Detect My Post Time
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-post-time/js/cfmpt-admin.js/wp-content/plugins/my-post-time/css/cfmpt-admin.cssHTML / DOM Fingerprints
cfmpt-text-optionsdata-cfmpt-progressbar-colorcfmpt_options_object[my_post_time]