
Bibs Twitter Follow Button Reloaded Security & Risk Analysis
wordpress.org/plugins/bibs-twitter-follow-button-reloadedGet the official Twitter Follow Button as a Widget or Shortcode for your website.
Is Bibs Twitter Follow Button Reloaded Safe to Use in 2026?
Generally Safe
Score 85/100Bibs Twitter Follow Button Reloaded has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bibs-twitter-follow-button-reloaded" plugin v1.1.2 exhibits a mixed security posture. On the positive side, it has a very small attack surface, with only one shortcode and no identified AJAX handlers, REST API routes, or cron events exposed without authentication. Furthermore, all SQL queries are confirmed to use prepared statements, and there are no file operations or external HTTP requests, which are good security practices. The absence of any recorded vulnerabilities in its history is also a strong indicator of a generally secure development history.
However, several concerning code signals present potential risks. The presence of the `create_function` function is a significant red flag, as it is considered deprecated and can lead to code injection vulnerabilities if not handled with extreme care, especially when dealing with user-supplied input. More critically, the output escaping is very poor, with only 18% of outputs properly escaped. This lack of output sanitization can pave the way for Cross-Site Scripting (XSS) attacks if any user-controlled data is rendered directly in the browser.
While the vulnerability history is clean, the identified code issues are concerning. The combination of a dangerous function and inadequate output escaping creates a tangible risk of XSS vulnerabilities. The plugin's limited attack surface and lack of complex interactions mitigate some of the potential impact, but the weaknesses in output handling are substantial and require attention.
Key Concerns
- Dangerous function used (create_function)
- Low percentage of properly escaped output
- No nonce checks found
- No capability checks found
Bibs Twitter Follow Button Reloaded Security Vulnerabilities
Bibs Twitter Follow Button Reloaded Code Analysis
Dangerous Functions Found
Output Escaping
Bibs Twitter Follow Button Reloaded Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Bibs Twitter Follow Button Reloaded Maintenance & Trust
Maintenance Signals
Community Trust
Bibs Twitter Follow Button Reloaded Alternatives
Feeds for Twitter – Embed Social Media Posts with Live Updates
easy-twitter-feeds
Embed Twitter Timeline/Feed, Post, Video, Hashtag, Follow Button, Tweet Button easily. This plugin is lightweight but super powerful.
BestWebSoft's Twitter
twitter-plugin
Add Twitter Follow, Tweet, Hashtag, and Mention buttons to WordPress posts and pages.
FireCask’s Twitter Follow Button
twitter-follow
Quickly adds the Twitter follow button. Can be easily implemented into your page, post or theme template
responsive-twitter-widget
responsive-twitter-widget
Responsive twitter widget will be shown very smoothly. It is very easy to setup . We can go to widget and drag drop .
AP Twitter Follow Button
ap-twitter-follow-button
AP Twitter Follow Button add a widget which allows you to add a highly cutomizable Twitter Follow Button.
Bibs Twitter Follow Button Reloaded Developer Profile
2 plugins · 20 total installs
How We Detect Bibs Twitter Follow Button Reloaded
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
http://platform.twitter.com/widgets.jsHTML / DOM Fingerprints
wpfollowbuttontwitter-follow-buttondata-show-countdata-langdata-buttondata-text-colordata-link-colordata-width+1 morewindow.twttr[tfb username='' count='' lang='' theme='