
Fetch Twitter Count Security & Risk Analysis
wordpress.org/plugins/fetch-twitter-count-for-wordpressReturns the current follower count of a specific Twitter account, or FALSE if not found. Can also use a shortcode.
Is Fetch Twitter Count Safe to Use in 2026?
Generally Safe
Score 85/100Fetch Twitter Count has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'fetch-twitter-count-for-wordpress' plugin v2017.08.13 presents a mixed security posture. On the positive side, it demonstrates good practices by having no known CVEs, no unpatched vulnerabilities, and utilizing prepared statements for all SQL queries. The absence of external HTTP requests and a small attack surface are also commendable. However, significant concerns arise from the code analysis. The plugin fails to perform output escaping on any of its outputs, leaving it vulnerable to Cross-Site Scripting (XSS) attacks. Additionally, there are no nonce or capability checks implemented, meaning that its single shortcode entry point could potentially be exploited without proper authorization if it handles sensitive data or performs actions that require user permissions. The lack of taint analysis results also makes it difficult to fully assess potential data leakage or injection vulnerabilities.
While the plugin has a clean vulnerability history, the identified code-level weaknesses, particularly the complete lack of output escaping and authorization checks on its entry point, introduce tangible risks. The absence of these fundamental security measures is a significant concern that outweighs the lack of historical vulnerabilities. Without addressing these issues, the plugin remains susceptible to exploitation, despite its otherwise clean record and good SQL handling.
Key Concerns
- No output escaping
- Missing nonce checks
- Missing capability checks
Fetch Twitter Count Security Vulnerabilities
Fetch Twitter Count Code Analysis
Output Escaping
Fetch Twitter Count Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Fetch Twitter Count Maintenance & Trust
Maintenance Signals
Community Trust
Fetch Twitter Count Alternatives
Share on Mastodon
share-on-mastodon
Automatically share WordPress posts on Mastodon.
WP REST Yoast Meta
wp-rest-yoast-meta
Adds meta tags as generated by Yoast SEO to the WP REST API. And adds a custom endpoint to retrieve all redirects as they are set in Yoast SEO Premium …
Divi Title Module
mc-divi-title-module
This plugin adds a new module to the Divi builder, it allows to easily insert titles without going through the text module.
Share on Pixelfed
share-on-pixelfed
Automatically share WordPress (image) posts on Pixelfed.
Add Image to RSS Feed
add-image-to-rss-feed
** this plugin is no longer being update. Please feel free to adopt me! **
Fetch Twitter Count Developer Profile
17 plugins · 130 total installs
How We Detect Fetch Twitter Count
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
horshipsrectors_twitter_count