
Readers Wall Security & Risk Analysis
wordpress.org/plugins/readers-wall高度自定制性能的读者墙
Is Readers Wall Safe to Use in 2026?
Generally Safe
Score 85/100Readers Wall has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "readers-wall" plugin version 1.3.7 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for its SQL queries and having a reported history free of any known CVEs. There are no external HTTP requests or file operations, which reduces the attack surface in those areas. However, significant concerns arise from the static analysis. The complete lack of output escaping for all identified output points is a critical weakness, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without sanitization. Furthermore, the absence of nonce and capability checks across all entry points, including the lack of authentication checks on any AJAX handlers or permission callbacks on REST API routes, represents a substantial risk. While the taint analysis did not reveal critical or high severity flows, the presence of unsanitized paths suggests that with a larger attack surface or more complex interactions, vulnerabilities could be introduced. The vulnerability history, while clean, could also indicate limited historical scrutiny. Overall, the lack of proper output escaping and authentication/authorization controls on all potential entry points are the most pressing issues.
Key Concerns
- 0% of output properly escaped
- 0 Nonce checks
- 0 Capability checks
- Unprotected AJAX handlers
- Unprotected REST API routes
- Flows with unsanitized paths
Readers Wall Security Vulnerabilities
Readers Wall Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Readers Wall Attack Surface
WordPress Hooks 2
Maintenance & Trust
Readers Wall Maintenance & Trust
Maintenance Signals
Community Trust
Readers Wall Alternatives
VK Link Target Controller
vk-link-target-controller
Redirect your visitors to another page than the post content when they click on the post title.
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
No External Links
mihdan-no-external-links
Convert external links into internal links, site wide or post/page specific. Add NoFollow, Click logging, and more...
Remove noreferrer
remove-noreferrer
"Remove noreferrer" automatically removes rel="noreferrer" attribute from links on your website on-the-fly.
Admin Collapse Subpages
admin-collapse-subpages
Using this plugin one can easily collapse/expand pages with children and grand children.
Readers Wall Developer Profile
3 plugins · 40 total installs
How We Detect Readers Wall
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/readers-wall/resource/default.pngHTML / DOM Fingerprints
RW-btnRW-btn-slide-textname="qw_RW_css"name="qw_RW_shortcode"name="qw_RW_shownumber"name="qw_RW_commentatleast"name="qw_RW_days"name="qw_RW_manualcss"+7 moreqwshowqwhide<a title="