Title: Question about safely installing plugins
Last modified: August 19, 2026

---

# Question about safely installing plugins

 *  Resolved [tomdkat](https://wordpress.org/support/users/tomdkat/)
 * (@tomdkat)
 * [3 days, 22 hours ago](https://wordpress.org/support/topic/question-about-safely-installing-plugins/)
 * Hi! Long time fan and user of Wordfence here. 🙂 In fact, Wordfence is one of
   the first plugins I install on every WordPress installation I do. 🙂
   So, I’m 
   looking for a plugin to estimate the reading time of posts. There are a bunch
   out there. I found a few that have been updated fairly frequently (w/in the past
   3-6 mos) yet they hardly have any users and not much activity in the support 
   forum. I’m concerned about installing a plugin that looks good, but that’s actually
   a “trap” of some kind. I trust Wordfence to protect my site, but I also don’t
   want to unintentionally install a plugin I shouldn’t install. lolI’m using the
   free version of Wordfence. Would this be sufficient to protect against installing
   a “questionable” plugin? Would Wordfence block a “bad” plugin at install time
   or only after it’s been activated or only during a scan?Thanks in advance!

Viewing 2 replies - 1 through 2 (of 2 total)

 *  Plugin Support [wfpeter](https://wordpress.org/support/users/wfpeter/)
 * (@wfpeter)
 * [3 days, 3 hours ago](https://wordpress.org/support/topic/question-about-safely-installing-plugins/#post-18998796)
 * Hi [@tomdkat](https://wordpress.org/support/users/tomdkat/), thank-you for your
   support and getting in touch!
 * We can’t recommend or check specific plugins here, but [Wordfence](https://www.wordfence.com/threat-intel/)
   and other researchers in the community are regularly helping to keep the WordPress
   ecosystem a safer place. A plugin being tested with a recent version of WordPress
   and available for download through the official repository (even with a small
   install-base) is a pretty good sign that it won’t immediately be flagged.
 * Wordfence has many rules and signatures in place to protect sites against emerging
   threats. Wordfence’s WAF can block requests if an uploaded or installed plugin
   immediately matches a known malicious file or exploit pattern. Daily quick-scans
   will also check your site for outdated plugins in addition to vulnerable ones.
 * Many thanks,
   Peter.
 *  Thread Starter [tomdkat](https://wordpress.org/support/users/tomdkat/)
 * (@tomdkat)
 * [2 days, 17 hours ago](https://wordpress.org/support/topic/question-about-safely-installing-plugins/#post-18999085)
 * Thanks for the reply and for the info!

Viewing 2 replies - 1 through 2 (of 2 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fquestion-about-safely-installing-plugins%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/wordfence/assets/icon.svg?rev=2070865)
 * [Wordfence Security - Firewall, Malware Scan, and Login Security](https://wordpress.org/plugins/wordfence/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wordfence/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wordfence/)
 * [Active Topics](https://wordpress.org/support/plugin/wordfence/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wordfence/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wordfence/reviews/)

 * 2 replies
 * 2 participants
 * Last reply from: [tomdkat](https://wordpress.org/support/users/tomdkat/)
 * Last activity: [2 days, 17 hours ago](https://wordpress.org/support/topic/question-about-safely-installing-plugins/#post-18999085)
 * Status: resolved