
TootPress Security & Risk Analysis
wordpress.org/plugins/tootpressTootPress copies your toots from Mastodon to WordPress.
Is TootPress Safe to Use in 2026?
Generally Safe
Score 100/100TootPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The tootpress plugin v0.5 exhibits a mixed security posture. On the positive side, static analysis reveals no critical or high severity taint flows, no dangerous functions, and a high percentage (93%) of properly escaped output, suggesting good practices in output sanitization. The absence of known CVEs and a clean vulnerability history further indicate a potentially stable and secure plugin. However, several significant concerns are present. The complete lack of nonce checks and capability checks across all analyzed entry points (even though the attack surface is reported as 0, this implies no explicitly exposed entry points were analyzed for these checks) is a major red flag. Additionally, 100% of the 12 SQL queries are not using prepared statements, which is a substantial risk for SQL injection vulnerabilities, especially if any input can indirectly influence these queries. The presence of file operations and external HTTP requests also warrants careful consideration, as these can be vectors for attack if not properly secured. While the plugin currently appears free of known vulnerabilities, the identified code-level weaknesses represent a latent risk that could be exploited in the future.
Key Concerns
- 100% of SQL queries are not prepared
- No nonce checks found
- No capability checks found
- File operations present without explicit checks
- External HTTP requests present without explicit checks
TootPress Security Vulnerabilities
TootPress Code Analysis
SQL Query Safety
Output Escaping
TootPress Attack Surface
WordPress Hooks 21
Scheduled Events 2
Maintenance & Trust
TootPress Maintenance & Trust
Maintenance Signals
Community Trust
TootPress Alternatives
Share on Mastodon
share-on-mastodon
Automatically share WordPress posts on Mastodon.
Simple Mastodon Verification
simple-mastodon-verification
Provides a General Settings menu option to define a rel=\"me\" in metatags for the whole site and also individual contributors.
Enable Mastodon Apps
enable-mastodon-apps
Allow accessing your WordPress with Mastodon clients. Just enter your own blog URL as your instance.
Link Verification for Mastodon
link-verification-for-mastodon
An unofficial WordPress plugin to quickly verify a link on your Mastodon profile.
Share on Bluesky
share-on-bluesky
A simple Crossposter for Bluesky (AT Protocol)
TootPress Developer Profile
2 plugins · 90 total installs
How We Detect TootPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tootpress/tootpress_toots.css/wp-content/plugins/tootpress/tootpress_tools.cssHTML / DOM Fingerprints
tootpress-is-heretootpress-is-not-here