
XPoster – Share to Bluesky and Mastodon Security & Risk Analysis
wordpress.org/plugins/wp-to-twitterPosts to Bluesky, Mastodon or X when you update your WordPress blog or add a link, with your chosen URL shortening service.
Is XPoster – Share to Bluesky and Mastodon Safe to Use in 2026?
Generally Safe
Score 99/100XPoster – Share to Bluesky and Mastodon has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-to-twitter" plugin v5.0.6 exhibits a generally strong security posture with many good practices in place. The code analysis reveals a robust implementation of prepared statements for SQL queries, a high percentage of properly escaped output, and a comprehensive use of nonce and capability checks. The attack surface is limited to a single AJAX handler, which importantly, appears to have an authentication check. Taint analysis did not reveal any critical or high severity flows, suggesting that user input is generally handled safely. However, the presence of the "unserialize" function is a potential concern as it can lead to deserialization vulnerabilities if used with untrusted input. The plugin's vulnerability history, while showing only one high severity CVE, indicates a past issue that warrants attention, even though it is currently patched. The single CVE being "Missing Authorization" highlights a historical area of weakness. Overall, the plugin demonstrates a good commitment to security, but the "unserialize" function and the historical vulnerability type suggest areas for continued vigilance.
Key Concerns
- Dangerous function unserialize found
- One high severity CVE in history
XPoster – Share to Bluesky and Mastodon Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
XPoster – Share to Bluesky and Mastodon Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
XPoster – Share to Bluesky and Mastodon Attack Surface
AJAX Handlers 1
WordPress Hooks 28
Scheduled Events 3
Maintenance & Trust
XPoster – Share to Bluesky and Mastodon Maintenance & Trust
Maintenance Signals
Community Trust
XPoster – Share to Bluesky and Mastodon Alternatives
NextScripts: Social Networks Auto-Poster
social-networks-auto-poster-facebook-twitter-g
Automatically publishes blogposts to profiles/pages/groups on Twitter, Google+, Pinterest, LinkedIn, Blogger, Tumblr ... 22 more
Revive Social – Social Media Auto Post and Scheduling Automation Plugin
tweet-old-post
Automatically share your WordPress posts on multiple social networks like Facebook, X (Twitter), LinkedIn, Instagram and more.
SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher
wp-scheduled-posts
Automate your WordPress content scheduling with a visual calendar, auto/manual schedulers, missed‑post handler, social sharing options & templates.
Genesis Club Lite
genesis-club-lite
Mobile Responsive Logos, Hamburger Menus, Animated Top Bars, FAQ Accordions, User Signatures, Google Calendars and much more for Genesis sites
Mastodon Autopost
autopost-to-mastodon
A Wordpress Plugin that automatically posts your new articles to Mastodon. The best: It is set and forget!
XPoster – Share to Bluesky and Mastodon Developer Profile
6 plugins · 96K total installs
How We Detect XPoster – Share to Bluesky and Mastodon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-to-twitter/css/wtt-admin.css/wp-content/plugins/wp-to-twitter/css/wtt-public.css/wp-content/plugins/wp-to-twitter/js/wtt-admin.js/wp-content/plugins/wp-to-twitter/js/wtt-public.jsXPoster/wp-content/plugins/wp-to-twitter/js/wtt-public.jswp-to-twitter/css/wtt-admin.css?ver=wp-to-twitter/css/wtt-public.css?ver=wp-to-twitter/js/wtt-admin.js?ver=wp-to-twitter/js/wtt-public.js?ver=HTML / DOM Fingerprints
wtt-messagewtt-postedwtt-error<!-- XPoster --><!-- XPoster - Share to Bluesky and Mastodon -->data-wtt-postiddata-wtt-servicedata-wtt-tweetidwtt_ajax_object