Reading Progress Tracker Security & Risk Analysis

wordpress.org/plugins/reading-progress-tracker

Adds a customizable reading progress bar to posts, with optional analytics and a reading-time estimate.

0 active installs v1.0.0 PHP 7.4+ WP 5.5+ Updated Nov 5, 2025
analyticsnext-articleprogressbarreadtimescroll
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Reading Progress Tracker Safe to Use in 2026?

Generally Safe

Score 100/100

Reading Progress Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The reading-progress-tracker plugin version 1.0.0 demonstrates a generally good security posture, especially considering its limited attack surface. The absence of vulnerabilities in its history and the strong implementation of security best practices like prepared statements for SQL queries, a high percentage of properly escaped output, and the presence of nonce and capability checks are positive indicators. The static analysis reveals no critical or high-severity code signals, including no dangerous functions, file operations, or external HTTP requests. Taint analysis also found no issues, suggesting that user input is being handled safely within the analyzed code flows.

However, a minor concern arises from the presence of two AJAX handlers, even though they are reported as protected by authentication checks in this analysis. The efficiency and completeness of these authentication checks would require further in-depth code review to be fully validated. The lack of any recorded vulnerabilities in the past is a strong positive, indicating consistent developer attention to security or a relatively simple codebase that hasn't attracted exploitative attention. Overall, this plugin appears to be built with security in mind, with only minor areas that might warrant further scrutiny in a more comprehensive audit.

Vulnerabilities
None known

Reading Progress Tracker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Reading Progress Tracker Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Reading Progress Tracker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
5
39 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

89% escaped44 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
wpaksreadprtrack_rpt_analytics_page (reading-progress-tracker.php:390)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Reading Progress Tracker Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_wpaksreadprtrack_rpt_save_scroll_depthreading-progress-tracker.php:134
noprivwp_ajax_wpaksreadprtrack_rpt_save_scroll_depthreading-progress-tracker.php:135
WordPress Hooks 7
actionadmin_enqueue_scriptsreading-progress-tracker.php:54
actionwp_enqueue_scriptsreading-progress-tracker.php:71
actionadmin_enqueue_scriptsreading-progress-tracker.php:99
actionadmin_enqueue_scriptsreading-progress-tracker.php:117
actionadmin_menureading-progress-tracker.php:194
actionadmin_initreading-progress-tracker.php:197
filterthe_contentreading-progress-tracker.php:517
Maintenance & Trust

Reading Progress Tracker Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 5, 2025
PHP min version7.4
Downloads201

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Reading Progress Tracker Developer Profile

rubigma

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Reading Progress Tracker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reading-progress-tracker/css/admin-rpt-style.css/wp-content/plugins/reading-progress-tracker/css/rpt-style.css/wp-content/plugins/reading-progress-tracker/js/rpt-script.js/wp-content/plugins/reading-progress-tracker/js/rpt-adblock-detect.js
Script Paths
https://payhip.com/payhip.js
Version Parameters
reading-progress-tracker/css/admin-rpt-style.css?ver=reading-progress-tracker/css/rpt-style.css?ver=reading-progress-tracker/js/rpt-script.js?ver=reading-progress-tracker/js/rpt-adblock-detect.js?ver=

HTML / DOM Fingerprints

JS Globals
wpaksreadprtrack_rptOptions
FAQ

Frequently Asked Questions about Reading Progress Tracker