
Clickit Readmore Security & Risk Analysis
wordpress.org/plugins/sylvie-readmore-toggleA lightweight and easy-to-use plugin that adds a customizable "Read More" toggle shortcode with a settings page to control button styles.
Is Clickit Readmore Safe to Use in 2026?
Generally Safe
Score 100/100Clickit Readmore has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sylvie-readmore-toggle" plugin v1.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, SQL queries without prepared statements, unescaped output, file operations, external HTTP requests, and any recorded vulnerabilities are all positive indicators. The plugin effectively utilizes prepared statements for its SQL queries and ensures all output is properly escaped, minimizing common web application vulnerabilities.
However, there are notable areas for improvement that introduce potential risks. The plugin lacks any nonce checks or capability checks, which are crucial for securing entry points. With one shortcode identified as the sole entry point, the absence of these security mechanisms presents a significant concern. A malicious actor could potentially exploit this shortcode without authentication or authorization, leading to unexpected behavior or even cross-site scripting (XSS) vulnerabilities if the shortcode's functionality is later expanded or altered. While the current taint analysis shows no critical or high-severity flows, this is likely due to the limited scope of the analysis (0 flows analyzed) and the lack of comprehensive security checks.
In conclusion, while the "sylvie-readmore-toggle" plugin demonstrates good development practices in areas like SQL query handling and output escaping, the complete absence of nonce and capability checks on its entry point is a critical oversight. This omission creates a notable security weakness that should be addressed promptly to prevent potential exploitation. The lack of historical vulnerabilities is encouraging, but it doesn't negate the need for fundamental security controls on all exposed functionalities.
Key Concerns
- Missing nonce checks on entry point
- Missing capability checks on entry point
Clickit Readmore Security Vulnerabilities
Clickit Readmore Code Analysis
Output Escaping
Clickit Readmore Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Clickit Readmore Maintenance & Trust
Maintenance Signals
Community Trust
Clickit Readmore Alternatives
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Futurio Extra
futurio-extra
Futurio Extra add extra features to Futurio theme like widgets, WooCommerce options, Elementor widgets, one click demo import and much more.
ND Shortcodes
nd-shortcodes
The plugin adds some useful components to your page builder ( Elementor or WP Bakery Page Builder ). All components are full responsive and retina rea …
Latest Post Shortcode
latest-post-shortcode
The "Latest Post Shortcode" allows you to create a dynamic content selection from your posts by combining, limiting, and filtering what you need.
AWSM Team – Team Showcase Plugin
awsm-team
AWSM Team is the most versatile and lite-weight WordPress plugin available to create and manage a team showcase.
Clickit Readmore Developer Profile
4 plugins · 10 total installs
How We Detect Clickit Readmore
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sylvie-readmore-toggle/clickit-readmore-script.js/wp-content/plugins/sylvie-readmore-toggle/clickit-readmore-style.cssclickit-readmore-script.jsclickit-readmore-script.js?ver=1.0clickit-readmore-style.css?ver=1.0HTML / DOM Fingerprints
clickit-readmore-containerclickit-readmore-toggleclickit-readmore-hiddendata-target<div class="clickit-readmore-container"><button class="clickit-readmore-toggle"<div id="