
Personal Tweet Me Button Security & Risk Analysis
wordpress.org/plugins/personal-tweet-meAdds the official tweet button, to your site as a sidebar widget. You can use a twitter account for the entire site, or use personal accounts per auth …
Is Personal Tweet Me Button Safe to Use in 2026?
Generally Safe
Score 85/100Personal Tweet Me Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The personal-tweet-me plugin v1.3 exhibits a generally good security posture, with no recorded vulnerabilities in its history and a clean taint analysis. The static analysis reveals a minimal attack surface, with no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication checks or permission callbacks. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are common vectors for vulnerabilities.
However, there are a few concerning areas. The presence of the `create_function` dangerous function is a significant red flag, as it can be exploited for arbitrary code execution if user input is directly incorporated into its arguments. Additionally, only 28% of output is properly escaped, indicating a substantial risk of cross-site scripting (XSS) vulnerabilities, especially since there are no explicit nonce checks present. While the plugin has a clean vulnerability history, this can be attributed to its small attack surface and lack of direct user input handling in its entry points, rather than inherently robust security practices across all code signals.
In conclusion, while the plugin is not actively vulnerable based on historical data and taint analysis, the static code analysis highlights critical areas for improvement. The use of `create_function` and the low output escaping rate present significant theoretical risks that could be exploited if user-controlled data ever reaches these parts of the code. The absence of nonce checks further exacerbates the XSS risk. Addressing these specific code signals is crucial for improving the plugin's overall security.
Key Concerns
- Dangerous function create_function detected
- Low output escaping percentage
- No nonce checks detected
Personal Tweet Me Button Security Vulnerabilities
Personal Tweet Me Button Code Analysis
Dangerous Functions Found
Output Escaping
Personal Tweet Me Button Attack Surface
WordPress Hooks 7
Maintenance & Trust
Personal Tweet Me Button Maintenance & Trust
Maintenance Signals
Community Trust
Personal Tweet Me Button Alternatives
Quotable Tweets by DraftPress
quotable-tweets
The Quotable Tweets plugin gives you an easy way to add a beautiful actionable tweet link to your sidebar.
rsh-Tweet
rsh-tweet-button
Adds the official Tweet Button from Twitter.com.
Skysa Tweet App
skysa-tweet-app
Let people share content on Twitter (a Tweet) without having to leave your web page. This app displays a Tweet button at the bottom of your site.
WP Tweet
wp-tweet
Adds the official Tweet Button from Twitter.
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Personal Tweet Me Button Developer Profile
1 plugin · 10 total installs
How We Detect Personal Tweet Me Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/personal-tweet-me/style.css/wp-content/plugins/personal-tweet-me/style.css?ver=HTML / DOM Fingerprints
twitter-share-buttondata-countdata-viadata-relateddata-counturldata-urldata-text