
BNS Twitter Follow Button Security & Risk Analysis
wordpress.org/plugins/bns-twitter-follow-buttonDisplays a Twitter Follow Button; and, includes shortcode functionality.
Is BNS Twitter Follow Button Safe to Use in 2026?
Use With Caution
Score 63/100BNS Twitter Follow Button has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "bns-twitter-follow-button" plugin exhibits a mixed security posture. While it demonstrates good practices by not making external HTTP requests and using prepared statements for all SQL queries, it has significant security concerns. The lack of any output escaping on 39 identified outputs is a critical vulnerability, creating a high risk of Cross-Site Scripting (XSS) attacks. Furthermore, the absence of nonce and capability checks on all entry points means that any of its functionalities could be exploited without proper authentication or authorization. The plugin's vulnerability history is also a major red flag, with one unpatched medium severity CVE for XSS. This, combined with the static analysis findings, indicates a pattern of insecure coding practices, particularly concerning input handling and output sanitization. The sole shortcode presents a potential, albeit limited, attack surface that is not adequately protected.
Key Concerns
- Unpatched CVE
- No output escaping
- No nonce checks
- No capability checks
BNS Twitter Follow Button Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
BNS Twitter Follow Button <= 0.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
BNS Twitter Follow Button Code Analysis
Output Escaping
BNS Twitter Follow Button Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
BNS Twitter Follow Button Maintenance & Trust
Maintenance Signals
Community Trust
BNS Twitter Follow Button Alternatives
Juiz Last Tweet Widget
juiz-last-tweet-widget
Add a widget to your sidebar to show your latest tweet(s) with style and without JavaScript! Retweet, Favorite and Reply links are available.
Metro Style Social Widget
metro-style-social-widget
Metro Style Social Network Widget
Social Media Badge Widget
social-media-badge-widget
This plugin creates a widget which easily displays the social badges from the leading social media websites in a clear an elegant way.
Social Icons Widget
social-icons-widget
A developer-friendly plugin that allows you to add a widget with links to various social media profiles.
Round Social Media Buttons
round-social-media-buttons
Provides a responsive social media widget that displays up to eight different social media websites.
BNS Twitter Follow Button Developer Profile
18 plugins · 2K total installs
How We Detect BNS Twitter Follow Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bns-twitter-follow-button/css/style.css/wp-content/plugins/bns-twitter-follow-button/js/widget.js//platform.twitter.com/widgets.js/wp-content/plugins/bns-twitter-follow-button/css/style.css?ver=/wp-content/plugins/bns-twitter-follow-button/js/widget.js?ver=HTML / DOM Fingerprints
bns-tfbuttontwitter-follow-buttondata-show-countdata-buttondata-text-colordata-link-colordata-widthdata-align+1 morewidgets[bns_tfbutton]