
Quotable Tweets by DraftPress Security & Risk Analysis
wordpress.org/plugins/quotable-tweetsThe Quotable Tweets plugin gives you an easy way to add a beautiful actionable tweet link to your sidebar.
Is Quotable Tweets by DraftPress Safe to Use in 2026?
Generally Safe
Score 85/100Quotable Tweets by DraftPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "quotable-tweets" plugin v1.1.7 presents a generally good security posture with no known vulnerabilities or critical static analysis findings. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface, which is a positive indicator. Furthermore, the fact that all SQL queries utilize prepared statements and there are no recorded file operations or external HTTP requests suggests careful development practices regarding data handling and external interactions.
However, a key concern is the low percentage (29%) of properly escaped output. This indicates a risk of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized data could be directly outputted into the browser. While no taint analysis flows were identified, this is likely due to the limited attack surface and lack of input sanitization checks present in the analyzed code signals. The absence of capability checks and nonce checks, coupled with the presence of an external HTTP request, raises potential security concerns that warrant further investigation, especially if the plugin were to gain more complex functionality or interact with user-submitted data in the future.
The plugin's vulnerability history is clean, with no known CVEs. This, combined with the static analysis results indicating no critical issues, suggests that the developers have maintained a good security focus. However, the limited output escaping remains a notable weakness. In conclusion, while "quotable-tweets" v1.1.7 appears relatively secure due to its small attack surface and lack of historical vulnerabilities, the significant unescaped output is a potential security risk that should be addressed.
Key Concerns
- Low output escaping (29% properly escaped)
- No capability checks present
- No nonce checks present
Quotable Tweets by DraftPress Security Vulnerabilities
Quotable Tweets by DraftPress Code Analysis
Output Escaping
Quotable Tweets by DraftPress Attack Surface
WordPress Hooks 2
Maintenance & Trust
Quotable Tweets by DraftPress Maintenance & Trust
Maintenance Signals
Community Trust
Quotable Tweets by DraftPress Alternatives
Personal Tweet Me Button
personal-tweet-me
Adds the official tweet button, to your site as a sidebar widget. You can use a twitter account for the entire site, or use personal accounts per auth …
rsh-Tweet
rsh-tweet-button
Adds the official Tweet Button from Twitter.com.
Skysa Tweet App
skysa-tweet-app
Let people share content on Twitter (a Tweet) without having to leave your web page. This app displays a Tweet button at the bottom of your site.
WP Tweet
wp-tweet
Adds the official Tweet Button from Twitter.
Easy Twitter Feed Widget Plugin
easy-twitter-feed-widget
Add twitter feeds on your WordPress site by using the Easy Twitter Feed Widget plugin.
Quotable Tweets by DraftPress Developer Profile
12 plugins · 613K total installs
How We Detect Quotable Tweets by DraftPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/quotable-tweets/quotable-tweets.cssquotable-tweets/quotable-tweets.css?ver=HTML / DOM Fingerprints
nnr-qt-containernnr-qt-title-containernnr-qt-icon-twitternnr-qt-titlennr-qt-text-containernnr-qt-post-titlennr-qt-quote-containernnr-qt-quote+1 moreid="nnrobots_quotable_tweets_widget_"name="nnrobots_quotable_tweets_widget_"id="nnrobots_quotable_tweets_title"name="nnrobots_quotable_tweets_title"id="nnrobots_quotable_tweets_bitly_access_token"name="nnrobots_quotable_tweets_bitly_access_token"+2 more