
Twitter Follow Button Security & Risk Analysis
wordpress.org/plugins/wplook-twitter-follow-button-newAdd the Twitter Follow Button to your blog to increase engagement and create a lasting connection with your audience.
Is Twitter Follow Button Safe to Use in 2026?
Generally Safe
Score 85/100Twitter Follow Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wplook-twitter-follow-button-new plugin, version 1.0.2, exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices regarding database interactions, as all SQL queries are properly prepared. The absence of file operations and external HTTP requests further reduces common attack vectors. The plugin also has no known historical vulnerabilities, which is a positive indicator.
However, several significant concerns are present in the static analysis. The use of the `create_function` is a critical security risk, as it can lead to arbitrary code execution if not handled with extreme care. Furthermore, a low percentage of output is properly escaped, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce checks and capability checks, combined with a zero attack surface reported, is perplexing and might indicate either a very limited plugin or an incomplete static analysis.
In conclusion, while the plugin's database interactions and lack of external dependencies are commendable, the presence of `create_function` and widespread unescaped output creates substantial security risks. The vulnerability history is clean, but this does not negate the immediate dangers identified in the code. Users should exercise caution due to the identified code quality issues.
Key Concerns
- Use of dangerous function create_function
- Low percentage of properly escaped output (potential XSS)
- Missing nonce checks
- Missing capability checks
Twitter Follow Button Security Vulnerabilities
Twitter Follow Button Code Analysis
Dangerous Functions Found
Output Escaping
Twitter Follow Button Attack Surface
WordPress Hooks 3
Maintenance & Trust
Twitter Follow Button Maintenance & Trust
Maintenance Signals
Community Trust
Twitter Follow Button Alternatives
Autopost for X (formerly Autoshare for Twitter)
autoshare-for-twitter
Automatically shares the post title or custom message and a link to the post to X/Twitter.
BestWebSoft's Twitter
twitter-plugin
Add Twitter Follow, Tweet, Hashtag, and Mention buttons to WordPress posts and pages.
FireCask’s Twitter Follow Button
twitter-follow
Quickly adds the Twitter follow button. Can be easily implemented into your page, post or theme template
Click To Tweet Block
click-to-tweeet-block
Gutenberg block to add a quote for visitors to tweet via Twitter.
Static Posts for Twitter – Embed x.com Tweets without an iframe
xeet-wp
Embed x.com Tweets without an iframe. No more cookies and save 500kb from your page load!
Twitter Follow Button Developer Profile
3 plugins · 1K total installs
How We Detect Twitter Follow Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wplook-twitter-follow-button-new/css/style.csswplook-twitter-follow-button-new/css/style.css?ver=HTML / DOM Fingerprints
id="WPLOOKTwitterFollowButton"name="WPLOOKTwitterFollowButton"id="wpl_title"name="wpl_title"id="wpl_username"name="wpl_username"+10 more