
Click To Tweet Boxes for Twitter By Cheeky Apps Security & Risk Analysis
wordpress.org/plugins/easy-click-to-tweet-by-cheeky-appsCreate beautiful and responsive "Click to Tweet" & "Tweet This" Boxes. Drive more social media Twitter traffic.
Is Click To Tweet Boxes for Twitter By Cheeky Apps Safe to Use in 2026?
Generally Safe
Score 85/100Click To Tweet Boxes for Twitter By Cheeky Apps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'easy-click-to-tweet-by-cheeky-apps' version 1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of critical code signals such as dangerous functions, raw SQL queries, and unsanitized taint flows is highly positive. Furthermore, a high percentage of output escaping and the presence of capability checks suggest developers have implemented good security practices. The plugin also has no recorded vulnerabilities (CVEs), historical or current, which further bolsters its security reputation.
However, a notable concern arises from the complete lack of nonce checks across its entry points. While there is only one shortcode entry point, and it's not explicitly marked as unprotected, the absence of nonces is a significant weakness. This could potentially leave the shortcode susceptible to Cross-Site Request Forgery (CSRF) attacks if the shortcode performs any actions that modify data or settings. The zero AJAX handlers and REST API routes without permission callbacks mitigate some of this risk by limiting the attack vectors, but the shortcode remains a point of concern.
In conclusion, this plugin demonstrates a robust foundation in secure coding practices, particularly in its handling of SQL and output. The lack of past vulnerabilities is encouraging. Nevertheless, the complete omission of nonce checks is a critical oversight that introduces a potential CSRF vulnerability. Addressing this single weakness would significantly enhance the plugin's overall security.
Key Concerns
- Missing nonce checks on entry points
Click To Tweet Boxes for Twitter By Cheeky Apps Security Vulnerabilities
Click To Tweet Boxes for Twitter By Cheeky Apps Code Analysis
Output Escaping
Click To Tweet Boxes for Twitter By Cheeky Apps Attack Surface
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
Click To Tweet Boxes for Twitter By Cheeky Apps Maintenance & Trust
Maintenance Signals
Community Trust
Click To Tweet Boxes for Twitter By Cheeky Apps Alternatives
Click To Tweet
click-to-tweet-by-todaymade
This plugin allows you to create beautiful Click To Tweet boxes anywhere in your blog post.
Vcgs Toolbox
vcgs-toolbox
Very simple plugin that includes some awesome options, features, shortcodes and scripts for improve your blogging experience.
Awesome Click To Tweet
awesome-click-to-tweet
The best click to tweet plugin. Insert customizable click to tweet boxes with customizable: fonts, templates, button text and animations into your Wor …
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Custom Twitter Feeds – A Tweets Widget or X Feed Widget
custom-twitter-feeds
Display X posts (Twitter tweets) from any public user account in a clean, attractive looking feed that updates weekly.
Click To Tweet Boxes for Twitter By Cheeky Apps Developer Profile
2 plugins · 30 total installs
How We Detect Click To Tweet Boxes for Twitter By Cheeky Apps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-click-to-tweet-by-cheeky-apps/assets/css/ca_click_to_tweet.css/wp-content/plugins/easy-click-to-tweet-by-cheeky-apps/assets/js/ca-clicktotweet-front.jsassets/js/ca-clicktotweet-front.jsca_click_to_tweet/assets/css/ca_click_to_tweet.css?ver=easy-click-to-tweet-by-cheeky-apps/assets/js/ca-clicktotweet-front.js?ver=HTML / DOM Fingerprints
click-to-tweetctt-theme-defaultctt-theme-basic-whitectt-theme-basic-borderctt-theme-basic-fullctt-theme-tweet-stringctt-theme-tweet-string-underlinedctt-theme-tweet-box-shadow+4 moredata-theme<div class="click-to-tweet<span class="click-to-tweet