
FireCask’s Twitter Follow Button Security & Risk Analysis
wordpress.org/plugins/twitter-followQuickly adds the Twitter follow button. Can be easily implemented into your page, post or theme template
Is FireCask’s Twitter Follow Button Safe to Use in 2026?
Generally Safe
Score 91/100FireCask’s Twitter Follow Button has a strong security track record. Known vulnerabilities have been patched promptly.
The "twitter-follow" plugin version 0.3 exhibits a generally good security posture concerning its direct code implementation. The static analysis reveals no dangerous functions, all SQL queries are prepared, and all output is properly escaped. There are no file operations or external HTTP requests, which are common sources of vulnerabilities. However, the complete absence of nonce checks and capability checks across all entry points is a significant concern. This means that any functionality exposed, even though it's limited to a single shortcode, is potentially susceptible to unauthorized execution if an attacker can trigger it. The vulnerability history indicates one past medium-severity Cross-Site Scripting (XSS) vulnerability, which, while no longer unpatched, suggests a historical tendency towards input sanitization issues. While the current code appears to have addressed past issues with output escaping, the lack of robust authorization checks on the shortcode leaves a potential opening.
Key Concerns
- Missing capability checks on entry points
- Missing nonce checks on entry points
- Past medium XSS vulnerability history
FireCask’s Twitter Follow Button Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Twitter Follow Button <= 0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via username Parameter
FireCask’s Twitter Follow Button Code Analysis
Output Escaping
FireCask’s Twitter Follow Button Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
FireCask’s Twitter Follow Button Maintenance & Trust
Maintenance Signals
Community Trust
FireCask’s Twitter Follow Button Alternatives
Customize Feeds for Twitter
twitter-tweets
Customize Feeds for Twitter plugin for WordPress. You can use this to display real time Twitter feeds on any where on your website by using shortcode …
Twiget Twitter Widget
twiget
A widget to display the latest Twitter status updates.
Ultimate Twitter Feeds
ultimate-twitter-feeds
Ultimate Twitter Feeds allows you to display customizable Twitter Tweets from any user timeline, any user Twitter List and single Tweet on your websi …
My Twitter Timelines
my-twitter-timelines
My Twitter Timelines is an all-in-one Twitter widget. With this widget, you can display the following: Twitter user timelines, User favorites, Search …
Ultimate twitter profile widget
ultimate-twitter-profile-widget
Ultimate twitter profile widget. Plugin shows your tweets on Page/Post/Widget area.
FireCask’s Twitter Follow Button Developer Profile
11 plugins · 4K total installs
How We Detect FireCask’s Twitter Follow Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twitter-follow/twitter-follow.phpHTML / DOM Fingerprints
twitter-follow-buttonWordPress Follow Button Shortcode for WordPress: https://firecask.com/services/development/wordpress/data-buttondata-text-colordata-link-colordata-show-countdata-lang<a href="https://twitter.com/" class="twitter-follow-button" rel="external nofollow">Follow @