Twitter Friendly Links Security & Risk Analysis

wordpress.org/plugins/twitter-friendly-links

Your very own TinyURL within your OWN domain! If you DO promote your blog posts in Twitter, then you MUST make your links look cool!

80 active installs v0.5 PHP + WP 2.8+ Updated May 19, 2010
linksshortsocialmediatwitterurl
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Twitter Friendly Links Safe to Use in 2026?

Generally Safe

Score 85/100

Twitter Friendly Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The 'twitter-friendly-links' plugin v0.5 exhibits a seemingly strong security posture based on the provided static analysis and vulnerability history. The plugin has no recorded vulnerabilities (CVEs) and the static analysis reveals a clean bill of health in terms of dangerous functions, SQL injections (all queries are prepared), file operations, and external HTTP requests. The absence of known issues in its vulnerability history is a positive indicator, suggesting it has historically been developed with security in mind or has been less of a target. The plugin also demonstrates zero attack surface points, which is ideal for minimizing potential entry points for attackers. Furthermore, the absence of taint flows with unsanitized paths is a significant strength, indicating no obvious pathways for malicious data to compromise the system. This suggests a developer who is conscious of input validation and sanitization. However, a significant concern arises from the extremely low percentage (3%) of properly escaped output. This indicates that user-generated or dynamic content displayed on the frontend is highly likely to be vulnerable to Cross-Site Scripting (XSS) attacks, a common and impactful vulnerability. While the plugin boasts a clean history and no direct code execution vulnerabilities, this widespread output escaping issue creates a substantial risk that could be exploited to compromise user sessions or deface websites.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Twitter Friendly Links Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Twitter Friendly Links Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
28
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

3% escaped29 total outputs
Attack Surface

Twitter Friendly Links Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
filtertemplate_redirecttwitter-friendly-links.php:84
actionadmin_menutwitter-friendly-links.php:85
actionadmin_noticestwitter-friendly-links.php:86
filtermanage_posts_columnstwitter-friendly-links.php:88
actionmanage_posts_custom_columntwitter-friendly-links.php:89
filtertweet_blog_post_urltwitter-friendly-links.php:93
filterthe_contenttwitter-friendly-links.php:95
filtersociable_linktwitter-friendly-links.php:97
filterretweet-anywhere-shortenerstwitter-friendly-links.php:99
actionwp_headtwitter-friendly-links.php:102
actioninittwitter-friendly-links.php:459
Maintenance & Trust

Twitter Friendly Links Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedMay 19, 2010
PHP min version
Downloads33K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

Twitter Friendly Links Developer Profile

Konstantin Kovshenin

15 plugins · 19K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Twitter Friendly Links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Twitter Friendly Links