
Retweet Anywhere Security & Risk Analysis
wordpress.org/plugins/retweet-anywhereRetweet Anywhere for WordPress is a nice and easy way to allow your readers to instantly retweet your blog posts through their Twitter accounts.
Is Retweet Anywhere Safe to Use in 2026?
Generally Safe
Score 100/100Retweet Anywhere has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "retweet-anywhere" plugin v0.1.3 presents a mixed security posture. While it exhibits some good practices such as using prepared statements for all SQL queries and a lack of known CVEs, it also contains significant security concerns. The presence of two AJAX handlers without authentication checks creates a notable attack surface, allowing unauthorized users to potentially trigger plugin functionality. Furthermore, the use of the `create_function` construct is a strong signal of potential security risks, as it can lead to arbitrary code execution if user input is not meticulously sanitized before being passed to it. The low percentage of properly escaped output (24%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the context of other users' browsers.
The plugin's vulnerability history is clean, with no recorded CVEs. This absence of past vulnerabilities might suggest a well-maintained or less complex plugin, or it could simply be a matter of time before issues are discovered, especially given the identified code signals. The combination of unprotected entry points and poor output sanitization, coupled with the use of `create_function`, points to a plugin that requires immediate attention to address potential security flaws before they can be exploited. While the lack of SQL injection risks is positive, the other identified weaknesses significantly outweigh this strength.
Key Concerns
- AJAX handlers without auth checks
- Unescaped output
- Dangerous function used (create_function)
- No nonce checks on AJAX
- No capability checks
Retweet Anywhere Security Vulnerabilities
Retweet Anywhere Code Analysis
Dangerous Functions Found
Output Escaping
Retweet Anywhere Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Retweet Anywhere Maintenance & Trust
Maintenance Signals
Community Trust
Retweet Anywhere Alternatives
MaxReTweet – Optimize your Twitter Headlines
maxretweet
Display a list of optimized Twitter headlines for each blog-posts. Increase your Twitter retweets % and inbound traffic.
Display Tweets
display-tweets-php
Display Tweets is an easy to use, future proof Twitter feed plugin that uses PHP to make requests to the v1.1 Twitter REST API.
Easy Retweet
easy-retweet
Adds a Tweet button to your WordPress posts
TweetMeme Button
tweetmeme-button
The TweetMeme Retweet button is the defacto standard in retweeting - used by some of the biggest websites in the world including Techcrunch.
TweetButton
tweetbutton-for-wordpress
Easily allows your blog post or page to be retweeted. Currently being used by SocialBrite and other members of the social media community.
Retweet Anywhere Developer Profile
15 plugins · 19K total installs
How We Detect Retweet Anywhere
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/retweet-anywhere/css/style.css/wp-content/plugins/retweet-anywhere/js/script.js/wp-content/plugins/retweet-anywhere/js/admin.jsretweet-anywhere/css/style.css?ver=retweet-anywhere/js/script.js?ver=HTML / DOM Fingerprints
widget-retweet-anywhereretweet-anywhere-widget-boxdata-rtw-titledata-rtw-formatdata-rtw-widthdata-rtw-heightretweet_anywhere_vars<div class='retweet-anywhere-widget-box'><em class='post_id'><em class='title'><em class='format'>