
Simple Reading Time Security & Risk Analysis
wordpress.org/plugins/simple-reading-timeThis plugin scans your article and generates average reading time, number of words divided by 200.
Is Simple Reading Time Safe to Use in 2026?
Generally Safe
Score 100/100Simple Reading Time has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The simple-reading-time plugin v1.0 demonstrates a strong security posture based on the provided static analysis. The complete absence of dangerous functions, SQL queries that are 100% prepared, and perfectly escaped output are excellent indicators of secure coding practices. Furthermore, the lack of file operations and external HTTP requests reduces the potential attack surface considerably. The plugin also shows no recorded vulnerabilities, CVEs, or common vulnerability types in its history, suggesting a well-maintained and secure codebase over time.
While the static analysis reveals no explicit security flaws or taint flows, a key area of concern is the complete lack of any protective mechanisms such as nonce checks or capability checks across its limited entry points. Although the current attack surface is zero, this absence means that if any entry points were to be introduced in future versions or if the plugin's functionality were to expand, they would inherently be unprotected. The vulnerability history being clean is a positive sign, but it doesn't negate the fundamental absence of security controls that could safeguard against unforeseen issues or evolving threats.
In conclusion, the current version of simple-reading-time appears to be highly secure due to its clean code and lack of historical vulnerabilities. However, the complete omission of authentication and authorization checks on its (currently non-existent) entry points represents a significant weakness. This is a missed opportunity to implement foundational security practices that would future-proof the plugin against potential risks as it evolves. The plugin is strong in its current implementation but lacks defensive depth.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
Simple Reading Time Security Vulnerabilities
Simple Reading Time Code Analysis
Simple Reading Time Attack Surface
WordPress Hooks 1
Maintenance & Trust
Simple Reading Time Maintenance & Trust
Maintenance Signals
Community Trust
Simple Reading Time Alternatives
Font Resize With Post Reading Time [GWE]
font-resizer-with-post-reading-time
With this plugin, you can easily display post reading time and a font resizing option on every single blog page.
Article Read Time
article-read-time
Displays estimated article reading time using shortcode or template tag with customizable formats.
My Post Time
my-post-time
My Post Time plugin is an innovative and useful plugin that is designed to help your readers more efficiently read your blog posts.
Ultimate Reading Time
ultimate-reading-time
Ultimate solution for displaying reading time on your posts and pages.
WB Content Stats
wb-content-stats
A simple plugin to showcase the word & character count and reading time.
Simple Reading Time Developer Profile
1 plugin · 0 total installs
How We Detect Simple Reading Time
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<small style='line-height: 5;'>🕐 <em>Average reading time: less than a minute.</em></small> <br><small style='line-height: 5;'>🕐 <em>Average reading time: $average_time minute(s) </em></small> <br>