
Display Tweets Security & Risk Analysis
wordpress.org/plugins/display-tweets-phpDisplay Tweets is an easy to use, future proof Twitter feed plugin that uses PHP to make requests to the v1.1 Twitter REST API.
Is Display Tweets Safe to Use in 2026?
Generally Safe
Score 85/100Display Tweets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The display-tweets-php plugin v1.0.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and performing capability checks and nonce checks, indicating an awareness of fundamental security principles. Furthermore, the complete absence of known CVEs and a clean vulnerability history suggest a generally stable and well-maintained codebase, at least in terms of publicly disclosed vulnerabilities.
However, significant concerns arise from the static code analysis. The presence of the `create_function` dangerous function is a critical red flag, as it can lead to arbitrary code execution if user-supplied input is not strictly sanitized before being passed to it. Additionally, a very low percentage (9%) of properly escaped output suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the page content displayed by the plugin. The single file operation and external HTTP request, while not inherently insecure, represent potential entry points for attacks if not handled with extreme care regarding user input.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices in SQL and authentication checks, the use of `create_function` and the widespread lack of output escaping introduce substantial risks. These code-level weaknesses overshadow the positive aspects and require immediate attention to mitigate potential XSS and arbitrary code execution vulnerabilities.
Key Concerns
- Dangerous function create_function used
- Low output escaping percentage (9%)
- Presence of file operations
- Presence of external HTTP requests
Display Tweets Security Vulnerabilities
Display Tweets Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Display Tweets Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Display Tweets Maintenance & Trust
Maintenance Signals
Community Trust
Display Tweets Alternatives
Twitterply
twitterply-for-webmasters
Want to display your twitter feeds or Tweets on your website or blog or in the sidebar. This plugin uses PHP to make requests to the Twitter REST API.
Peadig's Twitter Feed: Embedded Timeline WordPress Plugin
wp-twitter-feed
A simple Twitter feed that outputs your latest tweets in HTML into any post, page, template or sidebar widget. Customisable and easy to install!
Ultimate Twitter Feeds
ultimate-twitter-feeds
Ultimate Twitter Feeds allows you to display customizable Twitter Tweets from any user timeline, any user Twitter List and single Tweet on your websi …
Import Tweets as Posts
import-tweets-as-posts
"Import Tweets as Posts" plugin allows to easily import tweets from user's timeline or search query. It has also flexibility to import …
Timeline Twitter Feed
timeline-twitter-feed
Output timeline feeds and multiple hashtags into your WordPress site as flat HTML.
Display Tweets Developer Profile
1 plugin · 1K total installs
How We Detect Display Tweets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/display-tweets-php/display-tweets-php.php/wp-content/plugins/display-tweets-php/css/style.css/wp-content/plugins/display-tweets-php/js/jquery.fittext.js/wp-content/plugins/display-tweets-php/js/script.js/wp-content/plugins/display-tweets-php/js/jquery.fittext.js/wp-content/plugins/display-tweets-php/js/script.jsdisplay-tweets-php/css/style.css?ver=display-tweets-php/js/jquery.fittext.js?ver=display-tweets-php/js/script.js?ver=HTML / DOM Fingerprints
<!-- Display Tweets Plugin --><!-- /Display Tweets Plugin -->data-widget-iddisplayTweetsdtp[display_tweets