
Feeds for TikTok (TikTok feed, video, and gallery plugin) Security & Risk Analysis
wordpress.org/plugins/feeds-for-tiktokThe best way to display TikTok videos on your WordPress website. Display clean, customizable, and responsive TikTok feeds from your TikTok account.
Is Feeds for TikTok (TikTok feed, video, and gallery plugin) Safe to Use in 2026?
Generally Safe
Score 100/100Feeds for TikTok (TikTok feed, video, and gallery plugin) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "feeds-for-tiktok" v1.5.0 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to output escaping, with 100% of outputs properly escaped, and a high percentage of SQL queries utilizing prepared statements, indicating good coding practices. Furthermore, the absence of any recorded vulnerabilities in its history suggests a history of secure development and maintenance.
However, a significant concern lies in the presence of one AJAX handler that lacks authentication checks. This creates a potential entry point for attackers to interact with the plugin's functionality without proper authorization. While no critical or high-severity taint flows were identified, the two flows with unsanitized paths warrant attention, as they could potentially lead to unintended consequences if exploited in conjunction with other factors.
In conclusion, while the plugin benefits from robust output escaping and a clean vulnerability history, the unprotected AJAX handler represents a clear security weakness. Addressing this specific entry point should be the priority to further strengthen its overall security. The unsanitized paths, though not currently critical, should also be reviewed as a precautionary measure.
Key Concerns
- AJAX handler without auth checks
- Taint flows with unsanitized paths
Feeds for TikTok (TikTok feed, video, and gallery plugin) Security Vulnerabilities
Feeds for TikTok (TikTok feed, video, and gallery plugin) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Feeds for TikTok (TikTok feed, video, and gallery plugin) Attack Surface
AJAX Handlers 17
Shortcodes 1
WordPress Hooks 26
Scheduled Events 3
Maintenance & Trust
Feeds for TikTok (TikTok feed, video, and gallery plugin) Maintenance & Trust
Maintenance Signals
Community Trust
Feeds for TikTok (TikTok feed, video, and gallery plugin) Alternatives
QuadLayers TikTok Feed
wp-tiktok-feed
Display beautiful and responsive galleries on your website from your TikTok feed account.
Feed for TikTok
feed-for-tiktok
Displays the feed of any user on TikTok plus account information. Available for Elementor and shortcode.
Easy TikTok Feed – TikTok Video, Feed & Gallery Plugin
easy-tiktok-feed
Embed TikTok feeds in WordPress — responsive, SEO-ready, and monetization-friendly. No coding or tokens needed.
Custom Feed for TikTok – Social Post Feed Plugin for TikTok
custom-feed-for-tiktok
Explore the power of Custom Feed for TikTok, the top-notch plugin for displaying your videos with user-friendly and up-to-date features
Social Media Feed for WordPress
powr-social-feed
Keep your website content up to date and increase SEO by displaying all of your social media accounts, #hashtags in one place with customized design.
Feeds for TikTok (TikTok feed, video, and gallery plugin) Developer Profile
94 plugins · 23.5M total installs
How We Detect Feeds for TikTok (TikTok feed, video, and gallery plugin)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feeds-for-tiktok/assets/css/sbtt-oauth.css/wp-content/plugins/feeds-for-tiktok/assets/js/oauth-fragment-handler.js/wp-content/plugins/feeds-for-tiktok/assets/js/oauth-fragment-handler.js/wp-content/plugins/feeds-for-tiktok/assets/css/sbtt-oauth.css?ver=/wp-content/plugins/feeds-for-tiktok/assets/js/oauth-fragment-handler.js?ver=HTML / DOM Fingerprints
sbtt-admin-wrapperdata-nonce="sbtt-admin"data-ajaxurl="admin-ajax.php"sbtt_oauthsbtt_feed_options