Feed Widget for TikTok Security & Risk Analysis

wordpress.org/plugins/cm-tiktok-feed

Feed Widget for TikTok is a responsive slider widget that shows 20 latest images from a public TikTok user or a hashtag.

30 active installs v1.0.1 PHP 5.6+ WP 4.8+ Updated Jul 22, 2020
feedtiktokvideowidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Feed Widget for TikTok Safe to Use in 2026?

Generally Safe

Score 85/100

Feed Widget for TikTok has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "cm-tiktok-feed" plugin v1.0.1 exhibits a mixed security posture. While it demonstrates good practices such as 100% prepared statement usage for SQL queries and the absence of dangerous functions, there are significant areas of concern. The plugin has an attack surface of 5 entry points, with 2 (40%) of these AJAX handlers lacking authentication checks. This is a notable risk, as it potentially allows unauthenticated users to trigger plugin functionality. Furthermore, the taint analysis indicates 2 flows with unsanitized paths, although they are not classified as critical or high severity. The lack of vulnerability history might suggest a lack of prior exploitation or reporting, but this should not be mistaken for an assurance of security, especially given the identified unprotected entry points and unsanitized paths. The plugin also uses bundled libraries like TinyMCE and Freemius, which, if not kept updated, could introduce vulnerabilities.

Overall, the plugin's core data handling for SQL appears robust. However, the unprotected AJAX endpoints represent a direct and significant security risk that requires immediate attention. The presence of unsanitized paths, even if not currently critical, warrants further investigation to ensure they cannot be exploited to execute arbitrary code or manipulate data. The limited output escaping (13%) is another area that could be improved to mitigate cross-site scripting (XSS) vulnerabilities. The plugin's strengths lie in its SQL practices, but its weaknesses in input validation and authentication for AJAX handlers present a clear avenue for potential compromise.

Key Concerns

  • AJAX handlers without auth checks
  • Flows with unsanitized paths
  • Low percentage of properly escaped output
  • Bundled libraries (TinyMCE, Freemius)
Vulnerabilities
None known

Feed Widget for TikTok Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Feed Widget for TikTok Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
155
24 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
2

Bundled Libraries

TinyMCEFreemius

Output Escaping

13% escaped179 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
<tab-license> (admin\views\tab-license.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Feed Widget for TikTok Attack Surface

Entry Points5
Unprotected2

AJAX Handlers 4

authwp_ajax_wtik_check_licenseadmin\ajax\check-license.php:89
authwp_ajax_wtik_delete_accountincludes\class-plugin.php:85
authwp_ajax_wis_add_facebook_page_by_tokenincludes\class-tiktok-api.php:37
authwp_ajax_wtik_add_account_by_tokenincludes\class-tiktok-widget.php:120

Shortcodes 1

[cm_tiktok_feed] includes\class-tiktok-widget.php:115
WordPress Hooks 10
actionwbcr/isw/check_license_erroradmin\ajax\check-license.php:68
actionwbcr/isw/check_license_successadmin\ajax\check-license.php:82
actionadmin_noticescm-tiktok-feed.php:170
actionnetwork_admin_noticescm-tiktok-feed.php:171
actionwidgets_initcm-tiktok-feed.php:190
actionadmin_enqueue_scriptsincludes\class-plugin.php:114
actionwp_enqueue_scriptsincludes\class-plugin.php:130
actionwp_enqueue_scriptsincludes\class-tiktok-widget.php:109
actionadmin_enqueue_scriptsincludes\class-tiktok-widget.php:112
actionwtiktok_feedincludes\class-tiktok-widget.php:117
Maintenance & Trust

Feed Widget for TikTok Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJul 22, 2020
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Feed Widget for TikTok Developer Profile

Alexander Kovalev

6 plugins · 560 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Feed Widget for TikTok

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cm-tiktok-feed/admin/assets/css/wtik-admin-style.css/wp-content/plugins/cm-tiktok-feed/admin/assets/js/wtik-admin-script.js/wp-content/plugins/cm-tiktok-feed/libs/factory/core/assets/css/factory-bootstrap.css/wp-content/plugins/cm-tiktok-feed/libs/factory/core/assets/css/factory-style.css/wp-content/plugins/cm-tiktok-feed/libs/factory/core/assets/js/factory-bootstrap.js/wp-content/plugins/cm-tiktok-feed/libs/factory/forms/assets/css/factory-forms-style.css/wp-content/plugins/cm-tiktok-feed/libs/factory/forms/assets/js/factory-forms-script.js/wp-content/plugins/cm-tiktok-feed/libs/factory/pages/assets/css/factory-pages-style.css+1 more
Script Paths
/wp-content/plugins/cm-tiktok-feed/admin/assets/js/wtik-admin-script.js/wp-content/plugins/cm-tiktok-feed/libs/factory/core/assets/js/factory-bootstrap.js/wp-content/plugins/cm-tiktok-feed/libs/factory/forms/assets/js/factory-forms-script.js/wp-content/plugins/cm-tiktok-feed/libs/factory/pages/assets/js/factory-pages-script.js
Version Parameters
cm-tiktok-feed/admin/assets/css/wtik-admin-style.css?ver=cm-tiktok-feed/admin/assets/js/wtik-admin-script.js?ver=cm-tiktok-feed/libs/factory/core/assets/css/factory-bootstrap.css?ver=cm-tiktok-feed/libs/factory/core/assets/css/factory-style.css?ver=cm-tiktok-feed/libs/factory/core/assets/js/factory-bootstrap.js?ver=cm-tiktok-feed/libs/factory/forms/assets/css/factory-forms-style.css?ver=cm-tiktok-feed/libs/factory/forms/assets/js/factory-forms-script.js?ver=cm-tiktok-feed/libs/factory/pages/assets/css/factory-pages-style.css?ver=cm-tiktok-feed/libs/factory/pages/assets/js/factory-pages-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wtik-admin-page
Data Attributes
data-plugin-id="wtiktok"data-plugin-name="Feed Widget for TikTok"data-plugin-version="1.0.1"
JS Globals
wtik_plugin_info
FAQ

Frequently Asked Questions about Feed Widget for TikTok