
Custom Twitter Feeds – A Tweets Widget or X Feed Widget Security & Risk Analysis
wordpress.org/plugins/custom-twitter-feedsDisplay X posts (Twitter tweets) from any public user account in a clean, attractive looking feed that updates weekly.
Is Custom Twitter Feeds – A Tweets Widget or X Feed Widget Safe to Use in 2026?
Generally Safe
Score 97/100Custom Twitter Feeds – A Tweets Widget or X Feed Widget has a strong security track record. Known vulnerabilities have been patched promptly.
The custom-twitter-feeds plugin version 2.5.4 exhibits a mixed security posture. While it shows some positive signs like the absence of dangerous functions and a reasonable percentage of SQL queries using prepared statements, several areas raise concerns. The presence of 12 AJAX handlers without authentication checks is a significant risk, potentially allowing unauthorized users to interact with sensitive plugin functionality. Furthermore, taint analysis revealed 6 flows with unsanitized paths, including 2 of high severity, indicating potential vulnerabilities if these paths are exploited with malicious input. The plugin's vulnerability history is also noteworthy, with 7 known medium-severity CVEs primarily related to Cross-Site Request Forgery and Cross-Site Scripting. Although there are currently no unpatched CVEs, this pattern suggests a recurring tendency for these types of vulnerabilities to emerge, which warrants attention for ongoing secure development practices. In conclusion, while the plugin has strengths in its avoidance of dangerous functions and partial use of prepared statements, the significant number of unprotected AJAX endpoints, high-severity taint flows, and past vulnerability patterns necessitate caution and thorough auditing.
Key Concerns
- 12 AJAX handlers without authentication checks
- 2 high severity taint flows with unsanitized paths
- 6 flows with unsanitized paths
- 7 known medium severity CVEs in vulnerability history
Custom Twitter Feeds – A Tweets Widget or X Feed Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Custom Twitter Feeds <= 2.2.5 - Cross-Site Request Forgery to Cache Reset via ctf_clear_cache_admin Function
Custom Twitter Feeds (Tweets Widget) <= 2.2.3 - Cross-Site Request Forgery
Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.1 - Cross-Site Request Forgery to Plugin Options Update
Custom Twitter Feeds (Tweets Widget) <= 2.1.2 - Cross-Site Request Forgery
Custom Twitter Feeds (Tweets Widget) <= 1.8.4 - Cross-Site Request Forgery
Smash Balloon Plugins (Various Versions) - Reflected Cross-Site Scripting
Custom Twitter Feeds – A Tweets Widget or X Feed Widget Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Custom Twitter Feeds – A Tweets Widget or X Feed Widget Attack Surface
AJAX Handlers 47
Shortcodes 2
WordPress Hooks 74
Scheduled Events 8
Maintenance & Trust
Custom Twitter Feeds – A Tweets Widget or X Feed Widget Maintenance & Trust
Maintenance Signals
Community Trust
Custom Twitter Feeds – A Tweets Widget or X Feed Widget Alternatives
Ultimate Twitter Feeds
ultimate-twitter-feeds
Ultimate Twitter Feeds allows you to display customizable Twitter Tweets from any user timeline, any user Twitter List and single Tweet on your websi …
Easy Twitter Feed Widget Plugin
easy-twitter-feed-widget
Add twitter feeds on your WordPress site by using the Easy Twitter Feed Widget plugin.
WP Twitter Feeds
wp-twitter-feeds
WP Twitter Feeds - A simple widget which lets you add your latest tweets in just a few clicks on your website.
WP Twitter widget by rYokiNG
wp-twitter-widget-by-ryoking
free twitter widget for wordpress with api 1.1.
Customize Feeds for Twitter
twitter-tweets
Customize Feeds for Twitter plugin for WordPress. You can use this to display real time Twitter feeds on any where on your website by using shortcode …
Custom Twitter Feeds – A Tweets Widget or X Feed Widget Developer Profile
94 plugins · 23.5M total installs
How We Detect Custom Twitter Feeds – A Tweets Widget or X Feed Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-twitter-feeds/css/ctf-main.css/wp-content/plugins/custom-twitter-feeds/css/ctf-style.css/wp-content/plugins/custom-twitter-feeds/js/ctf-scripts.min.js/wp-content/plugins/custom-twitter-feeds/css/animate.min.css/wp-content/plugins/custom-twitter-feeds/css/sb-font-icons.css/wp-content/plugins/custom-twitter-feeds/css/sb-font-icons.css?ver=2.5.4/wp-content/plugins/custom-twitter-feeds/js/ctf-scripts.min.js?ver=2.5.4/wp-content/plugins/custom-twitter-feeds/js/ctf-scripts.min.jscustom-twitter-feeds/css/ctf-main.css?ver=custom-twitter-feeds/css/ctf-style.css?ver=custom-twitter-feeds/js/ctf-scripts.min.js?ver=custom-twitter-feeds/css/animate.min.css?ver=custom-twitter-feeds/css/sb-font-icons.css?ver=HTML / DOM Fingerprints
ctf-widgetctf-widget-titlectf-tweets-wrapctf-tweetctf-itemctf-tweet-textctf-tweet-metactf-tweet-actions+23 more<!-- Custom Twitter Feeds by Smash Balloon --><!-- Smash Balloon Custom Twitter Feed --><!--End Smash Balloon Custom Twitter Feed -->data-ctf-idctfSingleFeedAsyncInitctf_datactf_enqueue_scripts/wp-json/ctf/v1/feed/[custom-twitter-feed]