
Feed for TikTok Security & Risk Analysis
wordpress.org/plugins/feed-for-tiktokDisplays the feed of any user on TikTok plus account information. Available for Elementor and shortcode.
Is Feed for TikTok Safe to Use in 2026?
Generally Safe
Score 85/100Feed for TikTok has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The feed-for-tiktok v1.0.2 plugin exhibits a mixed security posture. On the positive side, it shows no known vulnerabilities in its history and adheres to good practices such as using prepared statements for all SQL queries and avoiding dangerous functions. It also has no recorded file operations or external HTTP requests, which are common vectors for compromise.
However, the static analysis reveals significant concerns, particularly regarding its attack surface. The presence of an unprotected AJAX handler is a critical security flaw that could allow unauthenticated users to trigger potentially harmful actions. Furthermore, a very low percentage of outputs are properly escaped, indicating a high risk of cross-site scripting (XSS) vulnerabilities across its various output points. The lack of capability checks on entry points also contributes to a weaker access control mechanism.
While the plugin has a clean vulnerability history, the current code analysis findings suggest a high potential for new vulnerabilities to exist, particularly XSS due to insufficient output sanitization and potential privilege escalation or denial of service via the unprotected AJAX handler. The absence of taint analysis flows is not necessarily a sign of security but could mean the tool couldn't analyze them or that the plugin avoids complex data flows.
In conclusion, the plugin's strengths lie in its SQL query handling and lack of historical vulnerabilities. However, the unprotected AJAX endpoint and widespread output escaping issues present immediate and serious risks that need to be addressed urgently.
Key Concerns
- Unprotected AJAX handler found
- Very low output escaping (2%)
- No capability checks on entry points
Feed for TikTok Security Vulnerabilities
Feed for TikTok Code Analysis
Output Escaping
Feed for TikTok Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 10
Maintenance & Trust
Feed for TikTok Maintenance & Trust
Maintenance Signals
Community Trust
Feed for TikTok Alternatives
QuadLayers TikTok Feed
wp-tiktok-feed
Display beautiful and responsive galleries on your website from your TikTok feed account.
Feeds for TikTok (TikTok feed, video, and gallery plugin)
feeds-for-tiktok
The best way to display TikTok videos on your WordPress website. Display clean, customizable, and responsive TikTok feeds from your TikTok account.
Custom Feed for TikTok – Social Post Feed Plugin for TikTok
custom-feed-for-tiktok
Explore the power of Custom Feed for TikTok, the top-notch plugin for displaying your videos with user-friendly and up-to-date features
Easy TikTok Feed – TikTok Video, Feed & Gallery Plugin
easy-tiktok-feed
Embed TikTok feeds in WordPress — responsive, SEO-ready, and monetization-friendly. No coding or tokens needed.
Gallery Feed for TikTok – Show TikTok Videos in Grid, Masonry, or Slideshow
ws-tiktok-feed
Embed TikTok videos and feeds in WordPress. Show likes, views, comments, shares & user info with Grid, Blog, Masonry, or Slideshow layouts.
Feed for TikTok Developer Profile
1 plugin · 200 total installs
How We Detect Feed for TikTok
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feed-for-tiktok/public/dist/css/tik-tok-feed.css/wp-content/plugins/feed-for-tiktok/admin/dist/js/tik-tok-feed.js/wp-content/plugins/feed-for-tiktok/public/dist/js/tik-tok-feed.js/wp-content/plugins/feed-for-tiktok/admin/dist/js/tik-tok-feed.js/wp-content/plugins/feed-for-tiktok/public/dist/js/tik-tok-feed.jsfeed-for-tiktok/public/dist/css/tik-tok-feed.css?ver=feed-for-tiktok/admin/dist/js/tik-tok-feed.js?ver=feed-for-tiktok/public/dist/js/tik-tok-feed.js?ver=HTML / DOM Fingerprints
tiktok-feed-containerdata-api-urldata-user-iddata-countdata-layoutdata-popupajax_tik_tok_feed_admin_object/wp-json/tiktok-feed/v1/get_user_feed/wp-json/tiktok-feed/v1/get_user_profile[tik-tok-feed][tik-tok-user-profile]