
Better Click To Share (Formerly Better Click To Tweet) Security & Risk Analysis
wordpress.org/plugins/better-click-to-tweetBetter Click To Share (formerly Better Click To Tweet) inserts styled call-out boxes into your posts so readers can share your content on X in one sim …
Is Better Click To Share (Formerly Better Click To Tweet) Safe to Use in 2026?
Generally Safe
Score 98/100Better Click To Share (Formerly Better Click To Tweet) has a strong security track record. Known vulnerabilities have been patched promptly.
The 'better-click-to-tweet' plugin version 6.0.0 presents a mixed security posture. While it demonstrates good practices in areas like SQL query sanitization, the presence of an unprotected REST API endpoint is a significant concern, increasing the potential attack surface. The 78% proper output escaping indicates a need for further review, as the remaining 22% could still be a vector for cross-site scripting vulnerabilities, especially when considering past vulnerabilities. The vulnerability history, including a high-severity Cross-Site Request Forgery (CSRF) and Improper Neutralization of Input During Web Page Generation (XSS) issues, suggests a pattern of past security weaknesses that require ongoing vigilance.
Despite the lack of currently unpatched CVEs and a generally low count of critical or high-severity taint flows, the unprotected REST API endpoint is a glaring weakness. The vulnerability history, particularly the types of past vulnerabilities, reinforces the need for thorough input validation and output escaping. While the plugin has strengths in its SQL handling and a reasonable number of capability checks, the identified entry points and historical data necessitate a cautious approach and ongoing monitoring.
Key Concerns
- Unprotected REST API route
- Output escaping is not 100% proper
- Vulnerability history includes high severity issues
- Flows with unsanitized paths found
Better Click To Share (Formerly Better Click To Tweet) Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Better Click To Tweet <= 5.10.3 - Cross-Site Request Forgery
Better Click To Tweet <= 5.10.3 - Missing Authorization
Better Click To Tweet <= 5.10.1 - Reflected Cross-Site Scripting
Better Click To Share (Formerly Better Click To Tweet) Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Better Click To Share (Formerly Better Click To Tweet) Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 26
Maintenance & Trust
Better Click To Share (Formerly Better Click To Tweet) Maintenance & Trust
Maintenance Signals
Community Trust
Better Click To Share (Formerly Better Click To Tweet) Alternatives
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Custom Twitter Feeds – A Tweets Widget or X Feed Widget
custom-twitter-feeds
Display X posts (Twitter tweets) from any public user account in a clean, attractive looking feed that updates weekly.
Comments – wpDiscuz
wpdiscuz
AJAX powered realtime comments. Designed to extend WordPress native comments. Custom comment forms/fields. Making comments has never been so awesome!
Open Graph and Twitter Card Tags
wonderm00ns-simple-facebook-open-graph-tags
Improve social media sharing by inserting Facebook Open Graph, Twitter Card, and SEO Meta Tags on your WordPress website pages, posts, WooCommerce pro …
Social Media Widget
social-media-widget
Adds links to all of your social media and sharing site profiles. Tons of icons come in 3 sizes, 4 icon styles, and 4 animations.
Better Click To Share (Formerly Better Click To Tweet) Developer Profile
3 plugins · 11K total installs
How We Detect Better Click To Share (Formerly Better Click To Tweet)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/better-click-to-tweet/assets/css/bctt-frontend.css/wp-content/plugins/better-click-to-tweet/assets/js/bctt-frontend.js/wp-content/plugins/better-click-to-tweet/assets/js/bctt-frontend.jsbetter-click-to-tweet/assets/css/bctt-frontend.css?ver=better-click-to-tweet/assets/js/bctt-frontend.js?ver=HTML / DOM Fingerprints
bctt-click-to-tweetbctt-ctt-textbctt-ctt-btndata-bctt-tweetdata-bctt-viadata-bctt-usernamedata-bctt-urldata-bctt-promptbctt_optionsbctt_frontend/bctt/v1/connector-agreement<aclass="twitter-share-button"href="https://twitter.com/intent/tweet?url=text=