
ReadMore ReadLess Security & Risk Analysis
wordpress.org/plugins/readmore-readlessReadMore ReadLess will hide content on page. Clicking on readmore will show complete page without refreshing the page.
Is ReadMore ReadLess Safe to Use in 2026?
Generally Safe
Score 85/100ReadMore ReadLess has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'readmore-readless' v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities (CVEs) and the plugin's clean vulnerability history are positive indicators. The code analysis shows a commendable adherence to security best practices, with no dangerous functions, SQL queries fully utilizing prepared statements, and a single nonce check and capability check present. There are also no detected taint flows, indicating a lack of obvious pathways for malicious data injection.
However, there is a minor concern regarding output escaping, where 40% of the outputs are not properly escaped. While the attack surface is reported as zero, this could still lead to cross-site scripting (XSS) vulnerabilities if unescaped output contains user-supplied data. The plugin also has no file operations or external HTTP requests, which further reduces potential attack vectors. The complete lack of AJAX handlers, REST API routes, shortcodes, and cron events also contributes to a minimal attack surface. Overall, the plugin is well-secured, with the primary area for improvement being the consistent proper escaping of all output.
Key Concerns
- Unescaped output identified
ReadMore ReadLess Security Vulnerabilities
ReadMore ReadLess Code Analysis
Output Escaping
ReadMore ReadLess Attack Surface
WordPress Hooks 4
Maintenance & Trust
ReadMore ReadLess Maintenance & Trust
Maintenance Signals
Community Trust
ReadMore ReadLess Alternatives
Gosign – ReadMore Toggle Text Block
gosign-readmore-toggle-text-block
Create Read More Toggle Text Block block with Latest Wordpress Gutenberg options and configurations.
ActionPress
actionpress
Replace the [...] more link with custom text for each post, creating a specific call-to-action.
Show Hide Content for Fusion Builder
show-hide-content-for-fusion-builder
Show Hide Read more button for Fusion Builder. It works well for the Avada theme.
Read More Without Refresh
read-more-without-refresh
Expand hidden content without page refresh. SEO-friendly, crawlable by search engines and easy to use.
Read More & Accordion
expand-maker
Easily hide or reveal long content with Read More buttons, accordions, and popups. Streamline your WordPress site's layout while enhancing user e …
ReadMore ReadLess Developer Profile
3 plugins · 350 total installs
How We Detect ReadMore ReadLess
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/readmore-readless/js/readmore.min.js/wp-content/plugins/readmore-readless/js/readmore.min.jsHTML / DOM Fingerprints
id="rmrl_meta_box_text"jQuery