
Read More Buddy Security & Risk Analysis
wordpress.org/plugins/read-more-buddyA simple and light but highly customizable to hide predefined text, through use of a shortcode and add a 'Read More' button.
Is Read More Buddy Safe to Use in 2026?
Generally Safe
Score 85/100Read More Buddy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "read-more-buddy" v1.0.0 plugin exhibits a mixed security posture. On the positive side, there are no known critical vulnerabilities (CVEs) or taint analysis findings, and the plugin uses prepared statements for all SQL queries. This suggests a generally good approach to common web application security risks. However, there are significant concerns related to output escaping and a lack of comprehensive security checks.
The plugin has a very low attack surface, with only one shortcode and no AJAX handlers, REST API routes, or cron events exposed without authentication. This is a strength. The primary concern lies in the output escaping, with only 13% of outputs properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the site through user-supplied data that is later displayed without proper sanitization. Furthermore, the complete absence of nonce checks and capability checks, even for the single shortcode, represents a weakness, as it implies insufficient authorization checks for potentially sensitive operations.
Given the lack of historical vulnerabilities, it's possible that the limited attack surface and the nature of the shortcode's functionality have not yet led to exploitable issues. However, the identified weaknesses in output escaping and authorization checks create a significant risk, particularly if user input is involved in the shortcode's processing or display. The plugin would greatly benefit from implementing robust output escaping for all user-facing content and incorporating nonce and capability checks where appropriate.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Read More Buddy Security Vulnerabilities
Read More Buddy Code Analysis
Output Escaping
Read More Buddy Attack Surface
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Read More Buddy Maintenance & Trust
Maintenance Signals
Community Trust
Read More Buddy Alternatives
Show/Hide Shortcode
showhide-shortcode
Small and efficient plugin implementing dynamic "Show more..." links. Just use the [showhide] shortcode, there is no addition to the backend.
KM-ShowHide
km-showhide
This simple plugin allows you to toggle your content inside shortcode.
FR Read More
fr-read-more
Create expandable content sections on WordPress. Let visitors reveal hidden content with a click.
Webspero Read More Toggle
webspero-read-more-toggle
Adds a simple "Read More / Read Less" toggle to long content using lightweight JavaScript. Ideal for blogs, FAQs, or excerpts.
Read More Without Refresh
read-more-without-refresh
Expand hidden content without page refresh. SEO-friendly, crawlable by search engines and easy to use.
Read More Buddy Developer Profile
1 plugin · 100 total installs
How We Detect Read More Buddy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/read-more-buddy/admin/css/read_mb-admin.css/wp-content/plugins/read-more-buddy/admin/js/read_mb-admin.js/wp-content/plugins/read-more-buddy/admin/js/shortcode.js/wp-content/plugins/read-more-buddy/admin/js/read_mb-admin.js/wp-content/plugins/read-more-buddy/admin/js/shortcode.jsread_mb-admin.css?ver=read_mb-admin.js?ver=HTML / DOM Fingerprints
window.rmb_mce_plugin