
Lastweets Security & Risk Analysis
wordpress.org/plugins/lastweetsDisplay a Twitter account latest tweets via a Gutenberg editor block.
Is Lastweets Safe to Use in 2026?
Generally Safe
Score 85/100Lastweets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'lastweets' plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of detectable AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code shows good practices with all SQL queries utilizing prepared statements and a high percentage of output being properly escaped. The lack of file operations, external HTTP requests, and the absence of any recorded vulnerabilities in its history further bolster its security profile.
However, a notable concern arises from the complete absence of nonce and capability checks across all identified entry points. While the current static analysis detected no entry points without these checks, this indicates a potential gap in its security implementation. If new entry points are introduced in future versions or if the analysis missed subtle ways these checks could be bypassed, this could lead to significant security risks. The taint analysis also revealed no flows, which is positive, but the lack of identified flows might also be a consequence of the limited attack surface or an incomplete taint analysis process.
In conclusion, 'lastweets' v1.0.0 appears to be a relatively secure plugin due to its minimal attack surface and good coding practices like prepared statements and output escaping. The absence of any historical vulnerabilities is a positive indicator. The primary weakness lies in the lack of explicit nonce and capability checks, which, if not addressed, could pose a future risk. The overall score reflects a solid foundation with a single significant area for improvement.
Key Concerns
- Missing nonce checks
- Missing capability checks
Lastweets Security Vulnerabilities
Lastweets Code Analysis
Output Escaping
Lastweets Attack Surface
WordPress Hooks 10
Maintenance & Trust
Lastweets Maintenance & Trust
Maintenance Signals
Community Trust
Lastweets Alternatives
Twitter Embed
twitter-embed
Easily embed tweets in your posts and pages by posting the tweet URL on a line by itself or by using a shortcode provided by the Twitter interface.
Get Tweets in PHP
get-tweets-in-php
Get latest tweets from a Twitter account with a couple of lines of PHP, and do anything you want with them.
Latest Tweets Tooltip
latest-tweets-tooltip
A wordpress plugin which will allow you to show the latest tweets about a certain word or phrase in a draggable and resizable jQuery tooltip window.
Modern Media Tweet Shortcode
modern-media-tweet-shortcode
Adds 'tweet' shortcode for embedding tweets using Twitter's shortcode format.
Easy Twitter Feed Widget Plugin
easy-twitter-feed-widget
Add twitter feeds on your WordPress site by using the Easy Twitter Feed Widget plugin.
Lastweets Developer Profile
2 plugins · 30 total installs
How We Detect Lastweets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lastweets/assets/css/theme.csslastweets/theme?ver=