Read Meter – Reading Time & Progress Bar Security & Risk Analysis

wordpress.org/plugins/read-meter

The Read Meter plugin displays the estimated reading time for blog posts along with a progress bar.

10K active installs v1.0.11 PHP 5.2+ WP 4.2+ Updated Jul 10, 2025
progressbarreadtime
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Read Meter – Reading Time & Progress Bar Safe to Use in 2026?

Generally Safe

Score 100/100

Read Meter – Reading Time & Progress Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The 'read-meter' plugin version 1.0.11 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and a high percentage of properly escaped output are excellent indicators of secure coding practices. The presence of nonce and capability checks on entry points further strengthens its defense against common web attacks.

The analysis also reveals no critical or high-severity issues in taint analysis, suggesting that data flowing through the plugin is generally handled safely. The plugin's vulnerability history is clean, with no recorded CVEs, which, combined with the static analysis, points to a well-maintained and secure codebase. However, the presence of a single shortcode as an entry point, while currently unprotected according to the data, warrants attention as it represents a potential avenue for attackers if not properly validated and sanitized within its implementation.

Overall, 'read-meter' appears to be a secure plugin with robust security controls. The lack of vulnerabilities and secure coding practices are commendable. The only minor area of concern is the unprotected shortcode entry point, which, in the absence of any known vulnerabilities or taint flows related to it, currently poses a low but non-zero risk. The plugin's strengths significantly outweigh its weaknesses.

Key Concerns

  • Unprotected shortcode entry point
Vulnerabilities
None known

Read Meter – Reading Time & Progress Bar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Read Meter – Reading Time & Progress Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
156 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped161 total outputs
Attack Surface

Read Meter – Reading Time & Progress Bar Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[read_meter] classes\class-bsfrt-readtime.php:76
WordPress Hooks 31
actionwp_enqueue_scriptsclasses\class-bsfrt-loader.php:61
actionadmin_enqueue_scriptsclasses\class-bsfrt-loader.php:63
actioninitclasses\class-bsfrt-loader.php:65
actioninitclasses\class-bsfrt-loader.php:67
actioninitclasses\class-bsfrt-loader.php:69
actionwpclasses\class-bsfrt-readtime.php:73
filtercomments_templateclasses\class-bsfrt-readtime.php:78
filterrender_blockclasses\class-bsfrt-readtime.php:81
filterthe_contentclasses\class-bsfrt-readtime.php:83
filtercomments_templateclasses\class-bsfrt-readtime.php:206
actionwp_headclasses\class-bsfrt-readtime.php:215
filternext_post_linkclasses\class-bsfrt-readtime.php:223
filterprevious_post_linkclasses\class-bsfrt-readtime.php:224
filterthe_contentclasses\class-bsfrt-readtime.php:233
filterthe_titleclasses\class-bsfrt-readtime.php:237
filterthe_titleclasses\class-bsfrt-readtime.php:241
filterget_the_excerptclasses\class-bsfrt-readtime.php:248
filterthe_contentclasses\class-bsfrt-readtime.php:250
filterthe_titleclasses\class-bsfrt-readtime.php:255
filterthe_titleclasses\class-bsfrt-readtime.php:259
filterget_the_excerptclasses\class-bsfrt-readtime.php:266
filterthe_contentclasses\class-bsfrt-readtime.php:269
filterthe_titleclasses\class-bsfrt-readtime.php:274
filterthe_titleclasses\class-bsfrt-readtime.php:278
actionwp_footerclasses\class-bsfrt-readtime.php:290
actionwp_footerclasses\class-bsfrt-readtime.php:294
actionwp_headclasses\class-bsfrt-readtime.php:300
actionwp_headclasses\class-bsfrt-readtime.php:304
actionwp_enqueue_scriptsclasses\class-bsfrt-readtime.php:1199
actionwp_headclasses\class-bsfrt-readtime.php:1208
actionadmin_menuincludes\bsf-rt-page.php:26
Maintenance & Trust

Read Meter – Reading Time & Progress Bar Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 10, 2025
PHP min version5.2
Downloads112K

Community Trust

Rating90/100
Number of ratings19
Active installs10K
Developer Profile

Read Meter – Reading Time & Progress Bar Developer Profile

Brainstorm Force

32 plugins · 8.6M total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
196 days
View full developer profile
Detection Fingerprints

How We Detect Read Meter – Reading Time & Progress Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/read-meter/assets/css/style.css/wp-content/plugins/read-meter/assets/js/read-meter.js/wp-content/plugins/read-meter/assets/css/backend-style.css/wp-content/plugins/read-meter/assets/js/backend-script.js
Script Paths
/wp-content/plugins/read-meter/assets/js/read-meter.js/wp-content/plugins/read-meter/assets/js/backend-script.js
Version Parameters
read-meter/assets/css/style.css?ver=read-meter/assets/js/read-meter.js?ver=read-meter/assets/css/backend-style.css?ver=read-meter/assets/js/backend-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
bsf-read-timebsf-progress-bar
Data Attributes
data-bsf-rt-words-per-minutedata-bsf-rt-reading-time-labeldata-bsf-rt-reading-time-postfix-label
JS Globals
bsf_rt_settings
FAQ

Frequently Asked Questions about Read Meter – Reading Time & Progress Bar