
Upvote / Downvote – Vote with a Tweet Security & Risk Analysis
wordpress.org/plugins/upvote-downvote-vote-with-a-tweetAllows users to vote on a topic using Twitter. Display results in standard banner sizes on posts, pages or widget. Optional Adsense Revenue Share.
Is Upvote / Downvote – Vote with a Tweet Safe to Use in 2026?
Generally Safe
Score 100/100Upvote / Downvote – Vote with a Tweet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "upvote-downvote-vote-with-a-tweet" plugin v1.4.1 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is highly positive. The presence of nonce checks and capability checks further strengthens its security by implementing fundamental WordPress security practices. Furthermore, the plugin has no recorded vulnerabilities, which suggests a history of stable and secure development.
However, a key area of concern arises from the output escaping. With 73% of outputs properly escaped, this leaves approximately 27% of outputs potentially unescaped. While the total number of outputs isn't explicitly stated as high, any unescaped output presents a risk of Cross-Site Scripting (XSS) vulnerabilities, particularly if user-supplied data is involved in these outputs.
The limited attack surface, consisting solely of a shortcode with no recorded unprotected entry points, is commendable. The lack of critical or high-severity taint flows is also a strong indicator of secure coding practices. In conclusion, the plugin is well-developed from a security standpoint, but the unescaped output is the primary weakness that requires attention to mitigate potential XSS risks.
Key Concerns
- Unescaped output present
Upvote / Downvote – Vote with a Tweet Security Vulnerabilities
Upvote / Downvote – Vote with a Tweet Code Analysis
Output Escaping
Upvote / Downvote – Vote with a Tweet Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Upvote / Downvote – Vote with a Tweet Maintenance & Trust
Maintenance Signals
Community Trust
Upvote / Downvote – Vote with a Tweet Alternatives
Upvotr
upvotr
A WordPress plugin to allow simple upvoting of post objects by a user.
WP-reddit
wp-reddit
Adds a link to respond to the post's individual listing on reddit, or submit a new listing.
Like Button Rating ♥ LikeBtn
likebtn-like-button
Add Like button to posts, pages, comments, WooCommerce, BuddyPress, bbPress, UM, custom posts! Sort content by likes! Get instant stats and insights!
bbPress Voting
bbp-voting
Let visitors vote up and down on bbPress topics and replies just like Reddit or Stack Overflow!
Polls CP
cp-polls
Create classic polls and advanced polls with dependant questions. Voting / survey system.
Upvote / Downvote – Vote with a Tweet Developer Profile
1 plugin · 10 total installs
How We Detect Upvote / Downvote – Vote with a Tweet
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/upvote-downvote-vote-with-a-tweet/udvote.css/wp-content/plugins/upvote-downvote-vote-with-a-tweet/udvote.js/wp-content/plugins/upvote-downvote-vote-with-a-tweet/udvote.jsupvote-downvote-vote-with-a-tweet/udvote.css?ver=upvote-downvote-vote-with-a-tweet/udvote.js?ver=HTML / DOM Fingerprints
udvote-bannerudvote-widgetdata-voteiddata-formatdata-typeudvote[udvote