Orbisius Quick Follow Security & Risk Analysis

wordpress.org/plugins/orbisius-quick-follow

Generates quick follow buttons for multiple twitter accounts e.g. follow the influencers.

10 active installs v1.0.0 PHP + WP 3.0+ Updated Unknown
followorbisiussocialtwitterwp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Orbisius Quick Follow Safe to Use in 2026?

Generally Safe

Score 100/100

Orbisius Quick Follow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "orbisius-quick-follow" v1.0.0 plugin exhibits a generally good security posture based on the provided static analysis. There are no detected dangerous functions, external HTTP requests, or file operations, which are common sources of vulnerabilities. The plugin also uses prepared statements for all its SQL queries, a crucial practice for preventing SQL injection. Furthermore, the absence of known CVEs and a clean vulnerability history is a positive indicator of its current security.

However, there are notable areas for improvement. The plugin lacks any nonce checks and capability checks. While the current attack surface is small and appears to have no direct unprotected entry points (AJAX, REST API), this absence of checks makes it vulnerable if new entry points are added in the future without proper security measures. The significantly low percentage of properly escaped output (7%) is a major concern, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially if the plugin processes any user-supplied data for display.

In conclusion, while the plugin benefits from a lack of known vulnerabilities and good practices in SQL handling and avoiding risky functions, the critical oversight in implementing nonce and capability checks, coupled with widespread output escaping deficiencies, presents a substantial risk. Future development should prioritize addressing these escape issues and implementing robust authorization checks.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Low output escaping percentage (7%)
Vulnerabilities
None known

Orbisius Quick Follow Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Orbisius Quick Follow Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
40
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

7% escaped43 total outputs
Attack Surface

Orbisius Quick Follow Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[orbisius_quick_follow] orbisius-quick-follow.php:105
WordPress Hooks 8
actioninitorbisius-quick-follow.php:29
actionwp_print_scriptsorbisius-quick-follow.php:30
actionwp_enqueue_scriptsorbisius-quick-follow.php:31
actionadmin_enqueue_scriptsorbisius-quick-follow.php:32
actionadmin_initorbisius-quick-follow.php:33
actionadmin_menuorbisius-quick-follow.php:34
actionwp_footerorbisius-quick-follow.php:35
filterplugin_action_linksorbisius-quick-follow.php:204
Maintenance & Trust

Orbisius Quick Follow Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Orbisius Quick Follow Developer Profile

Svetoslav Marinov

26 plugins · 12K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
722 days
View full developer profile
Detection Fingerprints

How We Detect Orbisius Quick Follow

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/orbisius-quick-follow/assets/main.css/wp-content/plugins/orbisius-quick-follow/assets/main.min.css
Version Parameters
/assets/main.css?ver=/assets/main.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
orbisius_quick_follow_list_itemorbisius_quick_follow_containerorbisius_quick_follow_listorbisius_quick_follow_gridorbisius_quick_follow_powered_by
HTML Comments
<!-- orbisius_quick_follow unrecognized: [
Data Attributes
data-show-count
JS Globals
orbisius_quick_follow_cfg
Shortcode Output
<div class='orbisius_quick_follow_list_item<div class='orbisius_quick_follow_container'<div class='orbisius_quick_follow_powered_by'Powered by <a href='http://club.orbisius.com/products/wordpress-plugins/orbisius-quick-follow/
FAQ

Frequently Asked Questions about Orbisius Quick Follow