
Reve Click2Tweet Security & Risk Analysis
wordpress.org/plugins/reve-click2tweetAdd totally custom, responsive and fast Click to tweet boxes to your WordPress site.
Is Reve Click2Tweet Safe to Use in 2026?
Generally Safe
Score 85/100Reve Click2Tweet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The reve-click2tweet plugin v1.3.0 demonstrates a generally good security posture based on the provided static analysis. It shows a very small attack surface, with only one shortcode identified as an entry point. Crucially, there are no identified AJAX handlers or REST API routes that lack authentication checks, which is a significant strength. The code also exclusively uses prepared statements for its SQL queries, mitigating the risk of SQL injection vulnerabilities. Furthermore, the absence of file operations and external HTTP requests reduces potential avenues for compromise.
However, there are areas for improvement. The most notable concern is the extremely low percentage of properly escaped output (2%). With 97 total outputs, this suggests that a large number of these outputs are potentially vulnerable to Cross-Site Scripting (XSS) attacks. While taint analysis found no unsanitized paths, the lack of output escaping creates a significant risk if any user-supplied data finds its way into these unescaped outputs. The absence of nonce checks on the identified shortcode also presents a potential issue, although its impact is mitigated by the lack of other vulnerable entry points.
The plugin's vulnerability history is clean, with no recorded CVEs. This suggests a history of stable and secure development. Coupled with the observed good practices in SQL querying and the limited attack surface, this plugin appears relatively safe from known historical vulnerabilities. Nevertheless, the significant output escaping deficiency remains a critical concern that warrants immediate attention to prevent potential XSS exploits.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce check on shortcode
Reve Click2Tweet Security Vulnerabilities
Reve Click2Tweet Release Timeline
Reve Click2Tweet Code Analysis
Output Escaping
Reve Click2Tweet Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Reve Click2Tweet Maintenance & Trust
Maintenance Signals
Community Trust
Reve Click2Tweet Alternatives
Lightshare – Lightweight Social Sharing
lightshare-social-sharing
A lightweight, high-performance social media sharing plugin for WordPress that won't slow down your site.
Social Snap — Social Share Buttons & Click to Tweet
socialsnap
Social sharing plugin with share buttons for Facebook, X (Twitter), LinkedIn and more. Includes Click to Tweet feature.
Custom Share Buttons with Floating Sidebar
custom-share-buttons-with-floating-sidebar
Share buttons with extra features to sharing your website posts/pages on Facebook, Twitter, Instagram, Whatsapp, Pinterest etc.
Spice Social Share
spice-social-share
Effortlessly add social share buttons to your posts.
Click To Tweet
click-to-tweet-by-todaymade
This plugin allows you to create beautiful Click To Tweet boxes anywhere in your blog post.
Reve Click2Tweet Developer Profile
2 plugins · 10 total installs
How We Detect Reve Click2Tweet
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reve-click2tweet/css/revec2t.cssreve-click2tweet/css/revec2t.css?ver=HTML / DOM Fingerprints
revec2t-share-boxdata-revec2t-labeldata-revec2t-icondata-revec2t-skindata-revec2t-hashtagsdata-revec2t-viadata-revec2t-short<div class="revec2t-share-box">