Click To Tweet Security & Risk Analysis

wordpress.org/plugins/click-to-tweet-by-todaymade

This plugin allows you to create beautiful Click To Tweet boxes anywhere in your blog post.

2K active installs v1.5 PHP + WP 3.1+ Updated Oct 9, 2025
click-to-tweettweettwittertwitter-boxestwitter-plugin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Click To Tweet Safe to Use in 2026?

Generally Safe

Score 100/100

Click To Tweet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The plugin 'click-to-tweet-by-todaymade' v1.5 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant strength, indicating a limited attack surface. Furthermore, the analysis shows no dangerous functions used, no file operations, and no external HTTP requests, all contributing to a safer implementation. The presence of capability checks and the use of prepared statements for SQL queries are also positive security indicators.

However, a notable concern arises from the output escaping analysis, where 100% of the single output found is not properly escaped. This presents a potential risk for cross-site scripting (XSS) vulnerabilities if the output contains user-controlled data. While the taint analysis shows no flows with unsanitized paths, this could be due to the limited complexity of the plugin or the specific test cases used. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting a stable and secure development over time. Overall, the plugin demonstrates good practices in limiting its attack surface and avoiding common vulnerable patterns, but the unescaped output requires attention to fully mitigate XSS risks.

Key Concerns

  • 100% of outputs not properly escaped
Vulnerabilities
None known

Click To Tweet Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Click To Tweet Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Click To Tweet Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionwp_enqueue_scriptstm-click-to-tweet.php:72
filterthe_contenttm-click-to-tweet.php:73
filtertiny_mce_versiontm-click-to-tweet.php:81
actionadmin_menutm-click-to-tweet.php:84
filterplugin_action_linkstm-click-to-tweet.php:87
actioninittm-click-to-tweet.php:90
filtermce_external_pluginstm-click-to-tweet.php:99
filtermce_buttonstm-click-to-tweet.php:100
actionadmin_inittm-click-to-tweet.php:131
Maintenance & Trust

Click To Tweet Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 9, 2025
PHP min version
Downloads97K

Community Trust

Rating80/100
Number of ratings14
Active installs2K
Developer Profile

Click To Tweet Developer Profile

CoSchedule

3 plugins · 6K total installs

81
trust score
Avg Security Score
90/100
Avg Patch Time
81 days
View full developer profile
Detection Fingerprints

How We Detect Click To Tweet

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/click-to-tweet-by-todaymade/assets/css/styles.css/wp-content/plugins/click-to-tweet-by-todaymade/assets/js/tmclicktotweet_plugin.js
Script Paths
/wp-content/plugins/click-to-tweet-by-todaymade/assets/js/tmclicktotweet_plugin.js

HTML / DOM Fingerprints

HTML Comments
<!-- A plugin by
Data Attributes
data-urldata-textdata-viadata-relateddata-counturldata-hashtags
JS Globals
tmclicktotweet
Shortcode Output
[Tweet
FAQ

Frequently Asked Questions about Click To Tweet