
WPTimeToRead Security & Risk Analysis
wordpress.org/plugins/wptimetoreadReading time.
Is WPTimeToRead Safe to Use in 2026?
Generally Safe
Score 85/100WPTimeToRead has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wptimetoread" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface, and crucially, there are no unprotected entry points identified. The code demonstrates good practices by exclusively using prepared statements for SQL queries and performing no file operations or external HTTP requests, further reducing potential vulnerabilities. The vulnerability history is clean, with no recorded CVEs, which suggests a well-maintained and secure codebase. However, a notable concern is the lack of output escaping. With 100% of identified outputs not properly escaped, this presents a risk of cross-site scripting (XSS) vulnerabilities if any dynamic content is ever introduced into the plugin's output. While the current lack of identified vulnerabilities is positive, the unescaped output is a critical weakness that needs to be addressed.
Key Concerns
- 100% of outputs not properly escaped
WPTimeToRead Security Vulnerabilities
WPTimeToRead Code Analysis
Output Escaping
WPTimeToRead Attack Surface
WordPress Hooks 14
Maintenance & Trust
WPTimeToRead Maintenance & Trust
Maintenance Signals
Community Trust
WPTimeToRead Alternatives
Reading Time WP
reading-time-wp
Reading Time WP creates an estimated reading time of your posts that is inserted above the content or by using a shortcode.
Worth The Read
worth-the-read
An adjustable progress meter showing how much of the post/page the user has scrolled through, and a read time commitment label near the post titles.
WP Reading Progress
wp-reading-progress
Light weight fully customizable reading progress bar. Sticks to top, bottom or sticky menu, with fallback for small screens. Includes ert (beta).
Just Writing Statistics
just-writing-statistics
Calculate your writing statistics on your WordPress site.
Post reading times
post-reading-times
A plugin that allows you to easily display the reading time of any article. Reading time is calculated based on a person's standard reading speed …
WPTimeToRead Developer Profile
1 plugin · 0 total installs
How We Detect WPTimeToRead
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wptimetoread/css/timetoread_admin.css/wp-content/plugins/wptimetoread/js/gsdom.js/wp-content/plugins/wptimetoread/js/timetoread_admin.js/wp-content/plugins/wptimetoread/css/wptimetoread.css/wp-content/plugins/wptimetoread/js/timetoread.js/wp-content/plugins/wptimetoread/js/gsdom.js/wp-content/plugins/wptimetoread/js/timetoread_admin.js/wp-content/plugins/wptimetoread/js/gsdom.js/wp-content/plugins/wptimetoread/js/timetoread.jsHTML / DOM Fingerprints
wptimetoreadtimetoread_params