Click To Tweet Boxes for Twitter By Cheeky Apps Security & Risk Analysis

wordpress.org/plugins/easy-click-to-tweet-by-cheeky-apps

Create beautiful and responsive "Click to Tweet" & "Tweet This" Boxes. Drive more social media Twitter traffic.

20 active installs v1.1 PHP + WP 1.0+ Updated Jun 6, 2016
click-to-tweettweet-boxtweet-thistwittertwitter-boxes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Click To Tweet Boxes for Twitter By Cheeky Apps Safe to Use in 2026?

Generally Safe

Score 85/100

Click To Tweet Boxes for Twitter By Cheeky Apps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The plugin 'easy-click-to-tweet-by-cheeky-apps' version 1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of critical code signals such as dangerous functions, raw SQL queries, and unsanitized taint flows is highly positive. Furthermore, a high percentage of output escaping and the presence of capability checks suggest developers have implemented good security practices. The plugin also has no recorded vulnerabilities (CVEs), historical or current, which further bolsters its security reputation.

However, a notable concern arises from the complete lack of nonce checks across its entry points. While there is only one shortcode entry point, and it's not explicitly marked as unprotected, the absence of nonces is a significant weakness. This could potentially leave the shortcode susceptible to Cross-Site Request Forgery (CSRF) attacks if the shortcode performs any actions that modify data or settings. The zero AJAX handlers and REST API routes without permission callbacks mitigate some of this risk by limiting the attack vectors, but the shortcode remains a point of concern.

In conclusion, this plugin demonstrates a robust foundation in secure coding practices, particularly in its handling of SQL and output. The lack of past vulnerabilities is encouraging. Nevertheless, the complete omission of nonce checks is a critical oversight that introduces a potential CSRF vulnerability. Addressing this single weakness would significantly enhance the plugin's overall security.

Key Concerns

  • Missing nonce checks on entry points
Vulnerabilities
None known

Click To Tweet Boxes for Twitter By Cheeky Apps Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Click To Tweet Boxes for Twitter By Cheeky Apps Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
63 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped67 total outputs
Attack Surface

Click To Tweet Boxes for Twitter By Cheeky Apps Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[Tweet] ca_shortcode.php:33
WordPress Hooks 19
actionwp_enqueue_scriptsca_shortcode.php:44
filterca_Tweet_shortcode_htmlca_shortcode.php:78
filterca_Tweet_shortcode_htmlca_shortcode.php:112
filterca_Tweet_shortcode_htmlca_shortcode.php:145
filterca_Tweet_shortcode_htmlca_shortcode.php:177
filterca_Tweet_shortcode_htmlca_shortcode.php:208
filterca_Tweet_shortcode_htmlca_shortcode.php:239
filterca_Tweet_shortcode_htmlca_shortcode.php:272
filterca_Tweet_shortcode_htmlca_shortcode.php:305
actionadmin_menuca_sidebar_menu.php:3
actionload-click-to-tweet_page_stuff-to-tweet2ca_sidebar_menu.php:97
actionadmin_footerca_sidebar_menu.php:121
actionadd_meta_boxesca_sidebar_menu.php:135
actionadmin_enqueue_scriptsca_sidebar_menu.php:170
actioninittweet-button.php:19
actionadmin_head-post.phptweet-button.php:21
actionadmin_head-post-new.phptweet-button.php:22
filtermce_external_pluginstweet-button.php:33
filtermce_buttonstweet-button.php:34
Maintenance & Trust

Click To Tweet Boxes for Twitter By Cheeky Apps Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJun 6, 2016
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings8
Active installs20
Developer Profile

Click To Tweet Boxes for Twitter By Cheeky Apps Developer Profile

scottmoses

2 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Click To Tweet Boxes for Twitter By Cheeky Apps

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-click-to-tweet-by-cheeky-apps/assets/css/ca_click_to_tweet.css/wp-content/plugins/easy-click-to-tweet-by-cheeky-apps/assets/js/ca-clicktotweet-front.js
Script Paths
assets/js/ca-clicktotweet-front.js
Version Parameters
ca_click_to_tweet/assets/css/ca_click_to_tweet.css?ver=easy-click-to-tweet-by-cheeky-apps/assets/js/ca-clicktotweet-front.js?ver=

HTML / DOM Fingerprints

CSS Classes
click-to-tweetctt-theme-defaultctt-theme-basic-whitectt-theme-basic-borderctt-theme-basic-fullctt-theme-tweet-stringctt-theme-tweet-string-underlinedctt-theme-tweet-box-shadow+4 more
Data Attributes
data-theme
Shortcode Output
<div class="click-to-tweet<span class="click-to-tweet
FAQ

Frequently Asked Questions about Click To Tweet Boxes for Twitter By Cheeky Apps