
oik-read-more Security & Risk Analysis
wordpress.org/plugins/oik-read-moreProgressively reveal content by clicking on "read more" buttons.
Is oik-read-more Safe to Use in 2026?
Generally Safe
Score 92/100oik-read-more has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "oik-read-more" plugin, version 0.2.6, presents a mixed security profile. On the positive side, there are no known CVEs, a clean vulnerability history, and the static analysis reveals a lack of dangerous functions, file operations, external HTTP requests, and external code execution opportunities. The plugin also does not appear to utilize any bundled libraries, which can sometimes introduce vulnerabilities. The absence of SQL queries using prepared statements is a strong indicator of good database security practices.
However, significant concerns arise from the output escaping analysis and the complete absence of security checks. The static analysis indicates that 100% of output is not properly escaped, which is a critical vulnerability. This means that any data rendered to the user, if it originates from user input or external sources, could be susceptible to Cross-Site Scripting (XSS) attacks. Furthermore, the complete lack of nonce checks and capability checks across all entry points (AJAX, REST API, shortcodes, cron) is highly alarming, as it suggests no authentication or authorization mechanisms are in place for these potential interaction points. The lack of taint analysis results is also noted, making it difficult to assess the flow of potentially malicious data.
In conclusion, while the plugin avoids common pitfalls like unpatched CVEs and dangerous functions, the lack of output escaping and authorization checks creates a substantial security risk, particularly for XSS vulnerabilities. The plugin's strengths lie in its clean history and careful database interaction, but these are overshadowed by critical weaknesses in how it handles user-facing output and secures its interaction points.
Key Concerns
- 100% of outputs are not properly escaped
- 0 nonce checks on entry points
- 0 capability checks on entry points
oik-read-more Security Vulnerabilities
oik-read-more Code Analysis
Output Escaping
oik-read-more Attack Surface
WordPress Hooks 5
Maintenance & Trust
oik-read-more Maintenance & Trust
Maintenance Signals
Community Trust
oik-read-more Alternatives
cookie-cat
cookie-cat
Assist compliance with UK cookie law/EU cookie directive by listing the cookies your website uses using the [cookies] shortcode. depends on oik.
oik-nivo-slider
oik-nivo-slider
[nivo] shortcode for the responsive jQuery "Nivo slider" for posts, pages, attachments and custom post types using oik
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
oik-read-more Developer Profile
16 plugins · 7K total installs
How We Detect oik-read-more
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[bw_more]