Read More About Security & Risk Analysis

wordpress.org/plugins/read-more-about

Allows users to add links in a story using a shortcode to provide addition reading material about a subject.

10 active installs v2.1.0 PHP 7.0+ WP 6.0+ Updated Unknown
custom-meta-panelrelated-linksshortcodes
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Read More About Safe to Use in 2026?

Generally Safe

Score 100/100

Read More About has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "read-more-about" v2.1.0 plugin exhibits a generally positive security posture, adhering to several good practices. The absence of known CVEs and critical taint flows is a significant strength, suggesting a history of secure development or minimal exposure. The plugin effectively utilizes prepared statements for all SQL queries, has no file operations or external HTTP requests, and includes both nonce and capability checks for its single entry point (a shortcode).

However, there are notable areas for improvement. The most significant concern is the low percentage of properly escaped output (11%). This indicates that user-supplied or dynamic data is likely being rendered directly into the HTML without sufficient sanitization, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the attack surface is small and protected, this output escaping deficiency could allow an attacker to inject malicious scripts through the shortcode's parameters if they are not adequately validated before output.

In conclusion, the plugin benefits from a clean vulnerability history and a focus on secure data handling for database interactions. Nevertheless, the prevalent lack of output escaping is a serious security weakness that needs immediate attention to mitigate the risk of XSS attacks. Addressing this will significantly improve the plugin's overall security.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Read More About Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Read More About Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
41
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

11% escaped46 total outputs
Attack Surface

Read More About Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[read-more] public\class-read-more-about-public.php:70
WordPress Hooks 13
actionadmin_initadmin\read-more-about-admin.php:34
actionsave_postadmin\read-more-about-admin.php:221
actionplugins_loadedincludes\class-read-more-about.php:109
actionadmin_enqueue_scriptsincludes\class-read-more-about.php:128
actionadmin_enqueue_scriptsincludes\class-read-more-about.php:129
actionadmin_menuincludes\class-read-more-about.php:130
actionsave_postincludes\class-read-more-about.php:131
actioninitincludes\class-read-more-about.php:132
actionrest_api_initincludes\class-read-more-about.php:133
actionwp_enqueue_scriptsincludes\class-read-more-about.php:143
actioninitincludes\class-read-more-about.php:144
actionwidgets_initincludes\class-read-more-about.php:145
actioninitincludes\class-read-more-about.php:155
Maintenance & Trust

Read More About Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedUnknown
PHP min version7.0
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Read More About Developer Profile

Jacob Martella

9 plugins · 230 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Read More About

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/read-more-about/admin/css/read-more-about-admin.css/wp-content/plugins/read-more-about/admin/js/read-more-about-admin.js/wp-content/plugins/read-more-about/public/css/read-more-about-public.css/wp-content/plugins/read-more-about/public/js/read-more-about-public.js/wp-content/plugins/read-more-about/blocks/build/index.js/wp-content/plugins/read-more-about/blocks/build/style-index.css
Script Paths
/wp-content/plugins/read-more-about/admin/js/read-more-about-admin.js/wp-content/plugins/read-more-about/public/js/read-more-about-public.js/wp-content/plugins/read-more-about/blocks/build/index.js
Version Parameters
read-more-about/admin/css/read-more-about-admin.css?ver=read-more-about/admin/js/read-more-about-admin.js?ver=read-more-about/public/css/read-more-about-public.css?ver=read-more-about/public/js/read-more-about-public.js?ver=read-more-about/blocks/build/index.js?ver=read-more-about/blocks/build/style-index.css?ver=

HTML / DOM Fingerprints

CSS Classes
read-more-about-wrapper
Data Attributes
data-read-more-about-id
JS Globals
readMoreAbout
REST Endpoints
/wp-json/read-more-about/v1/posts
Shortcode Output
[read_more_about]
FAQ

Frequently Asked Questions about Read More About