
Feed Widget for TikTok Security & Risk Analysis
wordpress.org/plugins/cm-tiktok-feedFeed Widget for TikTok is a responsive slider widget that shows 20 latest images from a public TikTok user or a hashtag.
Is Feed Widget for TikTok Safe to Use in 2026?
Generally Safe
Score 85/100Feed Widget for TikTok has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cm-tiktok-feed" plugin v1.0.1 exhibits a mixed security posture. While it demonstrates good practices such as 100% prepared statement usage for SQL queries and the absence of dangerous functions, there are significant areas of concern. The plugin has an attack surface of 5 entry points, with 2 (40%) of these AJAX handlers lacking authentication checks. This is a notable risk, as it potentially allows unauthenticated users to trigger plugin functionality. Furthermore, the taint analysis indicates 2 flows with unsanitized paths, although they are not classified as critical or high severity. The lack of vulnerability history might suggest a lack of prior exploitation or reporting, but this should not be mistaken for an assurance of security, especially given the identified unprotected entry points and unsanitized paths. The plugin also uses bundled libraries like TinyMCE and Freemius, which, if not kept updated, could introduce vulnerabilities.
Overall, the plugin's core data handling for SQL appears robust. However, the unprotected AJAX endpoints represent a direct and significant security risk that requires immediate attention. The presence of unsanitized paths, even if not currently critical, warrants further investigation to ensure they cannot be exploited to execute arbitrary code or manipulate data. The limited output escaping (13%) is another area that could be improved to mitigate cross-site scripting (XSS) vulnerabilities. The plugin's strengths lie in its SQL practices, but its weaknesses in input validation and authentication for AJAX handlers present a clear avenue for potential compromise.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths
- Low percentage of properly escaped output
- Bundled libraries (TinyMCE, Freemius)
Feed Widget for TikTok Security Vulnerabilities
Feed Widget for TikTok Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Feed Widget for TikTok Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Feed Widget for TikTok Maintenance & Trust
Maintenance Signals
Community Trust
Feed Widget for TikTok Alternatives
Feeds for TikTok (TikTok feed, video, and gallery plugin)
feeds-for-tiktok
The best way to display TikTok videos on your WordPress website. Display clean, customizable, and responsive TikTok feeds from your TikTok account.
QuadLayers TikTok Feed
wp-tiktok-feed
Display beautiful and responsive galleries on your website from your TikTok feed account.
Feed for TikTok
feed-for-tiktok
Displays the feed of any user on TikTok plus account information. Available for Elementor and shortcode.
Easy TikTok Feed – TikTok Video, Feed & Gallery Plugin
easy-tiktok-feed
Embed TikTok feeds in WordPress — responsive, SEO-ready, and monetization-friendly. No coding or tokens needed.
Widgets for Tiktok Feed
widgets-for-tiktok-video-feed
Tiktok Feed Widgets. Display your Tiktok feed on your website to increase engagement, sales and SEO.
Feed Widget for TikTok Developer Profile
6 plugins · 560 total installs
How We Detect Feed Widget for TikTok
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cm-tiktok-feed/admin/assets/css/wtik-admin-style.css/wp-content/plugins/cm-tiktok-feed/admin/assets/js/wtik-admin-script.js/wp-content/plugins/cm-tiktok-feed/libs/factory/core/assets/css/factory-bootstrap.css/wp-content/plugins/cm-tiktok-feed/libs/factory/core/assets/css/factory-style.css/wp-content/plugins/cm-tiktok-feed/libs/factory/core/assets/js/factory-bootstrap.js/wp-content/plugins/cm-tiktok-feed/libs/factory/forms/assets/css/factory-forms-style.css/wp-content/plugins/cm-tiktok-feed/libs/factory/forms/assets/js/factory-forms-script.js/wp-content/plugins/cm-tiktok-feed/libs/factory/pages/assets/css/factory-pages-style.css+1 more/wp-content/plugins/cm-tiktok-feed/admin/assets/js/wtik-admin-script.js/wp-content/plugins/cm-tiktok-feed/libs/factory/core/assets/js/factory-bootstrap.js/wp-content/plugins/cm-tiktok-feed/libs/factory/forms/assets/js/factory-forms-script.js/wp-content/plugins/cm-tiktok-feed/libs/factory/pages/assets/js/factory-pages-script.jscm-tiktok-feed/admin/assets/css/wtik-admin-style.css?ver=cm-tiktok-feed/admin/assets/js/wtik-admin-script.js?ver=cm-tiktok-feed/libs/factory/core/assets/css/factory-bootstrap.css?ver=cm-tiktok-feed/libs/factory/core/assets/css/factory-style.css?ver=cm-tiktok-feed/libs/factory/core/assets/js/factory-bootstrap.js?ver=cm-tiktok-feed/libs/factory/forms/assets/css/factory-forms-style.css?ver=cm-tiktok-feed/libs/factory/forms/assets/js/factory-forms-script.js?ver=cm-tiktok-feed/libs/factory/pages/assets/css/factory-pages-style.css?ver=cm-tiktok-feed/libs/factory/pages/assets/js/factory-pages-script.js?ver=HTML / DOM Fingerprints
wtik-admin-pagedata-plugin-id="wtiktok"data-plugin-name="Feed Widget for TikTok"data-plugin-version="1.0.1"wtik_plugin_info