
Reading Time Block Security & Risk Analysis
wordpress.org/plugins/reading-time-blockAdds a Gutenberg block to display the estimated reading time of the current post. Reading speed is customizable from the Settings → Reading screen.
Is Reading Time Block Safe to Use in 2026?
Generally Safe
Score 100/100Reading Time Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'reading-time-block' plugin v1.2.2 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is a positive indicator. The high percentage of properly escaped output further suggests good coding practices to prevent cross-site scripting vulnerabilities. The plugin also benefits from a very small attack surface, with no entry points identified in the static analysis, and a clean vulnerability history, indicating a lack of previously exploited weaknesses.
However, the complete lack of capability checks and nonce checks, particularly in conjunction with a zero attack surface, raises a slight concern. While currently there are no exposed entry points, if any were to be introduced in future versions, the absence of these essential security mechanisms could create vulnerabilities. The taint analysis showing zero flows is excellent, but it's important to remember that this analysis is only as good as the data it can analyze. In conclusion, the plugin appears to be very secure in its current state, with significant strengths in avoiding common vulnerability vectors. The primary area for potential improvement, though not an immediate risk given the current data, would be the inclusion of capability and nonce checks should the plugin's functionality evolve to require user interaction or data manipulation.
Key Concerns
- No capability checks detected
- No nonce checks detected
Reading Time Block Security Vulnerabilities
Reading Time Block Code Analysis
Output Escaping
Reading Time Block Attack Surface
WordPress Hooks 3
Maintenance & Trust
Reading Time Block Maintenance & Trust
Maintenance Signals
Community Trust
Reading Time Block Alternatives
Reading Time WP
reading-time-wp
Reading Time WP creates an estimated reading time of your posts that is inserted above the content or by using a shortcode.
Worth The Read
worth-the-read
An adjustable progress meter showing how much of the post/page the user has scrolled through, and a read time commitment label near the post titles.
WP Reading Progress
wp-reading-progress
Light weight fully customizable reading progress bar. Sticks to top, bottom or sticky menu, with fallback for small screens. Includes ert (beta).
Just Writing Statistics
just-writing-statistics
Calculate your writing statistics on your WordPress site.
Post reading times
post-reading-times
A plugin that allows you to easily display the reading time of any article. Reading time is calculated based on a person's standard reading speed …
Reading Time Block Developer Profile
4 plugins · 70 total installs
How We Detect Reading Time Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reading-time-block/assets/js/settings.js/wp-content/plugins/reading-time-block/block.jsHTML / DOM Fingerprints
reading_speed_optionsdata-value