Wpkmkz Tweet Blockquotes Security & Risk Analysis

wordpress.org/plugins/wpkmkz-tweet-blockquotes

Add a blockquote with a tweet button to share on twitter

10 active installs v1.3.3 PHP + WP 3.4+ Updated Apr 16, 2014
blockquotebootstraptweettwitterwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wpkmkz Tweet Blockquotes Safe to Use in 2026?

Generally Safe

Score 85/100

Wpkmkz Tweet Blockquotes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The wpkmkz-tweet-blockquotes plugin v1.3.3 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities through prepared statements, and proper output escaping are all positive indicators. The plugin also appears to have a minimal attack surface with no AJAX handlers or REST API routes, and importantly, no recorded vulnerability history, suggesting a history of stable and secure development.

However, the lack of nonce checks and capability checks on its single shortcode entry point presents a potential concern. While the attack surface is small, a vulnerable shortcode could still be exploited, especially in scenarios where user input is processed without proper validation or authorization. The presence of the TinyMCE library also warrants attention, as outdated versions of bundled libraries can introduce vulnerabilities, though no specific issues were flagged in the static analysis.

In conclusion, the plugin is well-developed with sound practices in critical areas like SQL and output handling. The primary area for improvement lies in fortifying its single entry point, the shortcode, with robust authorization and integrity checks. The absence of past vulnerabilities is a strong positive, but diligent ongoing security practices are always recommended.

Key Concerns

  • Shortcode missing nonce checks
  • Shortcode missing capability checks
  • Bundled library (TinyMCE) potential risk
Vulnerabilities
None known

Wpkmkz Tweet Blockquotes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Wpkmkz Tweet Blockquotes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

100% escaped2 total outputs
Attack Surface

Wpkmkz Tweet Blockquotes Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[TWEETBLOCK] wpkmkz-tweet-blockquotes.php:74
WordPress Hooks 3
actioninitwpkmkz-tweet-blockquotes.php:26
filtermce_external_pluginswpkmkz-tweet-blockquotes.php:29
filtermce_buttonswpkmkz-tweet-blockquotes.php:30
Maintenance & Trust

Wpkmkz Tweet Blockquotes Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedApr 16, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Wpkmkz Tweet Blockquotes Developer Profile

skapator

5 plugins · 3K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wpkmkz Tweet Blockquotes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpkmkz-tweet-blockquotes/css/style.css/wp-content/plugins/wpkmkz-tweet-blockquotes/js/wpkmkz-tweetblock.js
Script Paths
tinymce-button/wpkmkz-tweet-blockquotes.js

HTML / DOM Fingerprints

CSS Classes
wpkmkz-tweetblock
Data Attributes
data-textdata-shorturl
Shortcode Output
<blockquote class="wpkmkz-tweetblock" data-text= data-shorturl=
FAQ

Frequently Asked Questions about Wpkmkz Tweet Blockquotes