
LiveTwitch Security & Risk Analysis
wordpress.org/plugins/livetwitchWith this plugin you can display specified streams that are live on Twitch.tv
Is LiveTwitch Safe to Use in 2026?
Generally Safe
Score 85/100LiveTwitch has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The livetwitch plugin v0.0.3 exhibits a generally positive security posture based on the static analysis, with no critical or high severity vulnerabilities identified in taint analysis and a complete absence of known CVEs. The code demonstrates good practices by utilizing prepared statements for all SQL queries and performing at least one capability check, which are fundamental security measures. The limited attack surface, with no unprotected AJAX handlers or REST API routes, is also a strength. However, there are areas for concern. The most significant is the low percentage of properly escaped output (17%), which indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-provided data displayed on the frontend without proper sanitization could be exploited. Additionally, the lack of nonce checks on the identified entry points (shortcodes in this case) could potentially lead to Cross-Site Request Forgery (CSRF) if the shortcode functionality can be triggered by an unauthenticated or low-privileged user in a way that performs a sensitive action. The presence of external HTTP requests also warrants attention, as these could be leveraged for further attacks if not handled securely. While the plugin has no historical vulnerabilities, its current version's output escaping issues are a substantial weakness that needs immediate attention to mitigate XSS risks.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks on entry points
- External HTTP requests without explicit checks
LiveTwitch Security Vulnerabilities
LiveTwitch Release Timeline
LiveTwitch Code Analysis
Output Escaping
LiveTwitch Attack Surface
Shortcodes 1
WordPress Hooks 14
Scheduled Events 1
Maintenance & Trust
LiveTwitch Maintenance & Trust
Maintenance Signals
Community Trust
LiveTwitch Alternatives
Twitch Player
ttv-easy-embed-player
Twitch streams for your WordPress website - Twitch Player unlocks a compact, cinema-style layout, great for embedded stream experience.
Twitch Rail
ttv-easy-embed
Twitch streams for your WordPress website - Twitch Rail unlocks a horizontal scrolling layout, to display many streams in a small space.
Twitch Wall
ttv-easy-embed-wall
Twitch streams for your WordPress website - Twitch Wall unlocks a classic Twitch layout for displaying many streams at once.
Twitch TV Embed Suite
twitch-tv-embed-suite
Twitch TV Embed Suite allows easy placement of a twitch tv stream and/or chat anywhere on your WordPress site.
StreamWeasels Twitch Integration
streamweasels-twitch-integration
Embed Twitch streams with our collection of Twitch Blocks and Shortcodes. Works with Block Editor, Classic Editor, and Page Builders.
LiveTwitch Developer Profile
1 plugin · 10 total installs
How We Detect LiveTwitch
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/livetwitch/css/livetwitch-public.css/wp-content/plugins/livetwitch/js/livetwitch-public.js/wp-content/plugins/livetwitch/js/livetwitch-public.jslivetwitch/css/livetwitch-public.css?ver=livetwitch/js/livetwitch-public.js?ver=HTML / DOM Fingerprints
[livetwitch][livetwitch count=''][livetwitch singular=''][livetwitch count='' singular='']