Custom Feed for TikTok – Social Post Feed Plugin for TikTok Security & Risk Analysis

wordpress.org/plugins/custom-feed-for-tiktok

Explore the power of Custom Feed for TikTok, the top-notch plugin for displaying your videos with user-friendly and up-to-date features

1K active installs v1.2.1 PHP 7.4+ WP 6.2+ Updated Jan 29, 2026
tiktoktiktok-feedtiktok-gallerytiktok-plugintiktok-video
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Feed for TikTok – Social Post Feed Plugin for TikTok Safe to Use in 2026?

Generally Safe

Score 100/100

Custom Feed for TikTok – Social Post Feed Plugin for TikTok has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "custom-feed-for-tiktok" plugin v1.2.1 exhibits a strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices, with no detected dangerous functions, a complete reliance on prepared statements for SQL queries, and a high percentage of properly escaped output. The absence of file operations and external HTTP requests (which are often sources of vulnerabilities if not handled securely) further contributes to its strong profile. The vulnerability history is also clear, with no past or present CVEs, indicating a potentially well-maintained and secure codebase.

However, the analysis does reveal some areas that warrant attention. The complete lack of nonce checks and capability checks across all entry points (AJAX, REST API, shortcodes, cron events) is a significant concern. While the static analysis indicates zero entry points, the absence of these fundamental security mechanisms means that if any entry points were to be introduced or discovered in the future, they would likely be unprotected. The absence of taint analysis results also prevents a deeper understanding of potential data flow vulnerabilities.

In conclusion, "custom-feed-for-tiktok" v1.2.1 appears to be a robust plugin with sound coding practices regarding SQL and output handling, backed by a clean vulnerability history. Its primary weakness lies in the complete omission of fundamental WordPress security checks like nonces and capability checks, which could pose a risk if the attack surface expands. While the current attack surface is reported as zero, this oversight leaves room for potential future vulnerabilities if not addressed.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • No taint flow analysis results available
Vulnerabilities
None known

Custom Feed for TikTok – Social Post Feed Plugin for TikTok Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Feed for TikTok – Social Post Feed Plugin for TikTok Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
174 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

99% escaped176 total outputs
Attack Surface

Custom Feed for TikTok – Social Post Feed Plugin for TikTok Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionwpsr_tiktok_send_email_reportapp\Services\Platforms\Feeds\Tiktok\TiktokFeed.php:44
actioninitapp\Services\Widgets\Beaver\BeaverWidget.php:14
actionelementor/frontend/after_register_stylesapp\Services\Widgets\ElementorWidget.php:14
actionelementor/frontend/after_enqueue_stylesapp\Services\Widgets\ElementorWidget.php:15
actionelementor/widgets/registerapp\Services\Widgets\ElementorWidget.php:16
actioninitapp\Services\Widgets\Oxygen\OxygenWidget.php:24
actionoxygen_add_plus_wpsocialninja_section_contentapp\Services\Widgets\Oxygen\OxygenWidget.php:25
actionwp_footerapp\Services\Widgets\Oxygen\TikTokWidget.php:467
actionadmin_noticescustom-feed-for-tiktok-boot.php:44
actioninitcustom-feed-for-tiktok-boot.php:113
actionwp_social_reviews_loaded_v2custom-feed-for-tiktok.php:24
Maintenance & Trust

Custom Feed for TikTok – Social Post Feed Plugin for TikTok Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version7.4
Downloads13K

Community Trust

Rating80/100
Number of ratings1
Active installs1K
Developer Profile

Custom Feed for TikTok – Social Post Feed Plugin for TikTok Developer Profile

Deb Nath Utpol

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Feed for TikTok – Social Post Feed Plugin for TikTok

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Custom Feed for TikTok – Social Post Feed Plugin for TikTok