
AP Twitter Follow Button Security & Risk Analysis
wordpress.org/plugins/ap-twitter-follow-buttonAP Twitter Follow Button add a widget which allows you to add a highly cutomizable Twitter Follow Button.
Is AP Twitter Follow Button Safe to Use in 2026?
Generally Safe
Score 85/100AP Twitter Follow Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ap-twitter-follow-button" plugin v0.9.3 exhibits a mixed security posture. On the positive side, there are no recorded CVEs, suggesting a history of relative stability. The plugin also demonstrates good practices regarding SQL queries, as all are using prepared statements, and there are no file operations or external HTTP requests, which reduces common attack vectors. However, several significant concerns arise from the static analysis. The presence of a 'create_function' call is a notable risk, as this function is deprecated and can be exploited to execute arbitrary code in certain contexts. Furthermore, only 10% of outputs are properly escaped, indicating a high likelihood of cross-site scripting (XSS) vulnerabilities, which could allow attackers to inject malicious scripts into pages. The lack of nonce checks and capability checks on entry points, while the attack surface is reported as zero, means that if any entry points are ever introduced or discovered, they would be unprotected.
The complete absence of taint analysis data and a zero-count for known vulnerabilities might indicate thorough past security efforts or simply a lack of deep analysis. However, the 'create_function' and the significantly low output escaping percentage are clear indicators of present risks that require immediate attention. The plugin's strengths lie in its clean database interaction and lack of external dependencies, but the high risk of XSS and the use of a dangerous function are critical weaknesses that overshadow these benefits. A balanced conclusion is that while the plugin has a clean vulnerability history, the static analysis reveals serious flaws that elevate its risk profile considerably.
Key Concerns
- Dangerous function create_function used
- Low output escaping (10%)
- No nonce checks
- No capability checks
AP Twitter Follow Button Security Vulnerabilities
AP Twitter Follow Button Code Analysis
Dangerous Functions Found
Output Escaping
AP Twitter Follow Button Attack Surface
WordPress Hooks 1
Maintenance & Trust
AP Twitter Follow Button Maintenance & Trust
Maintenance Signals
Community Trust
AP Twitter Follow Button Alternatives
Feeds for Twitter – Embed Social Media Posts with Live Updates
easy-twitter-feeds
Embed Twitter Timeline/Feed, Post, Video, Hashtag, Follow Button, Tweet Button easily. This plugin is lightweight but super powerful.
BestWebSoft's Twitter
twitter-plugin
Add Twitter Follow, Tweet, Hashtag, and Mention buttons to WordPress posts and pages.
FireCask’s Twitter Follow Button
twitter-follow
Quickly adds the Twitter follow button. Can be easily implemented into your page, post or theme template
responsive-twitter-widget
responsive-twitter-widget
Responsive twitter widget will be shown very smoothly. It is very easy to setup . We can go to widget and drag drop .
Twitter Follow Button
twitter-follow-button-plugin
With this plugin, you can embed Twitter Follow Button to let your visitor follow you instantly by just clicking on the button.
AP Twitter Follow Button Developer Profile
1 plugin · 90 total installs
How We Detect AP Twitter Follow Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ap-twitter-follow-button/ap-twitter-follow-button.php/wp-content/plugins/ap-twitter-follow-button/ap-twitter-follow-button.php?ver=HTML / DOM Fingerprints
ap_twitter_follow_buttondata-show-countdata-show-screen-namedata-dntdata-sizedata-langdata-widthtwitter-wjs<a href="https://twitter.com/class="twitter-follow-button"