
Reading Time & Word Count Block for Post Security & Risk Analysis
wordpress.org/plugins/reading-time-word-count-block-for-postDisplay reading time and word count for posts and also simple use shortcode ['reading-time']. Automatically or via shortcode. Simple and SEO-friendly.
Is Reading Time & Word Count Block for Post Safe to Use in 2026?
Generally Safe
Score 92/100Reading Time & Word Count Block for Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'reading-time-word-count-block-for-post' plugin version 1.0.0 exhibits a generally good security posture based on the provided static analysis. The plugin demonstrates strong practices by utilizing prepared statements for all SQL queries, ensuring all output is properly escaped, and not making external HTTP requests or file operations. The absence of known vulnerabilities in its history further reinforces this positive outlook, suggesting a diligent approach to security by the developers.
However, a significant concern arises from the presence of an unprotected AJAX handler. This creates a direct entry point for potential malicious input that is not validated or authorized, which could be exploited if an attacker can trigger this handler with carefully crafted data. While taint analysis did not reveal any unsanitized paths or critical/high severity flows, the unprotected AJAX handler remains a notable weakness that should be addressed to improve the plugin's overall security resilience.
In conclusion, the plugin has strong foundational security practices. The primary weakness is the unprotected AJAX endpoint, which, despite a clean taint analysis history, presents a tangible risk. Addressing this specific entry point would significantly bolster the plugin's security.
Key Concerns
- Unprotected AJAX handler
Reading Time & Word Count Block for Post Security Vulnerabilities
Reading Time & Word Count Block for Post Release Timeline
Reading Time & Word Count Block for Post Code Analysis
Output Escaping
Data Flow Analysis
Reading Time & Word Count Block for Post Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Reading Time & Word Count Block for Post Maintenance & Trust
Maintenance Signals
Community Trust
Reading Time & Word Count Block for Post Alternatives
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
BoldGrid Easy SEO – Simple and Effective SEO
boldgrid-easy-seo
Easy SEO helps you easily create keyword rich content and rank higher in the search engines.
Reading Time WP
reading-time-wp
Reading Time WP creates an estimated reading time of your posts that is inserted above the content or by using a shortcode.
Semrush SEO Writing Assistant
semrush-seo-writing-assistant
The Semrush SEO Writing Assistant provides instant recommendations for content optimization based on the best-performing articles in Google's top 10.
Turn Rank Math FAQ Block to Accordion
turn-rank-math-faq-block-to-accordion
This plugin turns Rank Math FAQ blocks into accordion easily and make them accessibility ready.
Reading Time & Word Count Block for Post Developer Profile
2 plugins · 20 total installs
How We Detect Reading Time & Word Count Block for Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reading-time-word-count-block-for-post/admin/css/reading-time-word-count-block-post-admin.css/wp-content/plugins/reading-time-word-count-block-for-post/admin/js/reading-time-word-count-block-post-admin.js/wp-content/plugins/reading-time-word-count-block-for-post/admin/js/reading-time-word-count-block-post-admin.jsreading-time-word-count-block-post/admin/css/reading-time-word-count-block-post-admin.css?ver=reading-time-word-count-block-post/admin/js/reading-time-word-count-block-post-admin.js?ver=HTML / DOM Fingerprints
name="rtwcbfp_show_word_count"name="rtwcbfp_show_with_title"name="rtwcbfp_show_with_content"name="rtwcbfp_show_reading_time"name="rtwcbfp_reading_time_label"name="rtwcbfp_reading_time_label_singular"+5 more[reading_time]