Rocket Reader (Speed-Reader) Security & Risk Analysis

wordpress.org/plugins/rocket-reader-speed-reader

Introduction

20 active installs v1.6.2 PHP + WP 2.8+ Updated May 6, 2022
readerspeedspeed-readerspeed-reading
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Rocket Reader (Speed-Reader) Safe to Use in 2026?

Generally Safe

Score 85/100

Rocket Reader (Speed-Reader) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin "rocket-reader-speed-reader" v1.6.2 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly reduces its attack surface. Furthermore, the code signals reveal excellent practices regarding SQL queries (all prepared statements) and a complete absence of dangerous functions or file operations. The presence of a nonce check is also a positive indicator. However, a notable concern is the low percentage (41%) of properly escaped output. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if malicious data is introduced and rendered without adequate sanitization, particularly affecting logged-in users viewing content generated by the plugin.

The plugin's vulnerability history is exceptionally clean, with zero recorded CVEs of any severity. This suggests a history of responsible development and maintenance, or that the plugin has not been a significant target for attackers. While the lack of a large attack surface contributes to this, the limited output escaping remains a weakness that could be exploited. In conclusion, "rocket-reader-speed-reader" v1.6.2 is generally well-secured with very low risk, primarily due to its limited entry points and secure handling of critical operations like database queries. The main area for improvement and a potential, albeit low, risk lies in addressing the inconsistent output escaping.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

Rocket Reader (Speed-Reader) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Rocket Reader (Speed-Reader) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
13
9 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

41% escaped22 total outputs
Attack Surface

Rocket Reader (Speed-Reader) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitrvg-rocket-reader.php:38
actioninitrvg-rocket-reader.php:54
actionwp_footerrvg-rocket-reader.php:65
actionwp_footerrvg-rocket-reader.php:66
actionwp_footerrvg-rocket-reader.php:68
filterthe_contentrvg-rocket-reader.php:70
actionadmin_initrvg-rocket-reader.php:74
actionadmin_menurvg-rocket-reader.php:75
Maintenance & Trust

Rocket Reader (Speed-Reader) Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedMay 6, 2022
PHP min version
Downloads13K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

Rocket Reader (Speed-Reader) Developer Profile

cageehv

3 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Rocket Reader (Speed-Reader)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rocket-reader-speed-reader/css/rr_rocket_reader_fe.css/wp-content/plugins/rocket-reader-speed-reader/css/rr_rocket_reader_be.css/wp-content/plugins/rocket-reader-speed-reader/js/rr_rocket_reader.js
Script Paths
/wp-content/plugins/rocket-reader-speed-reader/js/rr_rocket_reader.js
Version Parameters
rocket-reader-speed-reader/css/rr_rocket_reader_fe.css?ver=rocket-reader-speed-reader/css/rr_rocket_reader_be.css?ver=rocket-reader-speed-reader/js/rr_rocket_reader.js?ver=

HTML / DOM Fingerprints

CSS Classes
dlg-no-closeui-dialog-titlebar-closedlg-no-titleui-dialog-titlebar
HTML Comments
START Rocket Reader v1.6.2 [01/28/2017 | http://cagewebdev.com/rocket-reader | CAGE Web Design | Rolf van GelderEND Rocket Reader
Data Attributes
data-rr-wpmdata-rr-use-popupdata-rr-cont-bgcolordata-rr-cont-bordercolordata-rr-textcolordata-rr-bgcolor+2 more
JS Globals
rr_init_versionrr_init_WPMrr_init_use_popuprr_init_cont_bgcolorrr_init_cont_bordercolorrr_init_textcolor+13 more
FAQ

Frequently Asked Questions about Rocket Reader (Speed-Reader)