
Multi Account Tweet Feeds by Webline Security & Risk Analysis
wordpress.org/plugins/multi-account-tweet-feeds-by-weblineA Simple plugin to show latest Tweets from a multiple Twitter accounts in the same sidebar widget,post,page or text widget content.
Is Multi Account Tweet Feeds by Webline Safe to Use in 2026?
Generally Safe
Score 85/100Multi Account Tweet Feeds by Webline has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "multi-account-tweet-feeds-by-webline" v1.0.7 exhibits a mixed security posture. On the positive side, it boasts a clean vulnerability history with no known CVEs, suggesting a history of secure development or diligent patching. The code analysis reveals a strong adherence to secure database practices with all SQL queries using prepared statements. Furthermore, the absence of critical taint analysis findings and dangerous functions is encouraging.
However, several areas raise concerns. The plugin has a notable lack of security checks, with zero nonce checks and zero capability checks across its entry points. While the attack surface is small (one shortcode), its lack of protective measures means any discovered vulnerability could be easily exploitable. The output escaping is also a significant weakness, with less than half of the outputs properly escaped, creating a risk of Cross-Site Scripting (XSS) vulnerabilities. The single file operation and external HTTP request, while not inherently problematic, become higher risk due to the absence of input validation and sanitization that is not detailed in this analysis.
In conclusion, while the plugin avoids common and severe vulnerabilities like SQL injection and has a clean history, the lack of authentication and authorization checks, coupled with poor output escaping, presents a substantial risk of XSS and potential privilege escalation if further weaknesses are present but not revealed in this static analysis. The absence of taint analysis flow data also leaves a gap in understanding potential complex exploit chains.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Low output escaping rate
Multi Account Tweet Feeds by Webline Security Vulnerabilities
Multi Account Tweet Feeds by Webline Code Analysis
Output Escaping
Multi Account Tweet Feeds by Webline Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Multi Account Tweet Feeds by Webline Maintenance & Trust
Maintenance Signals
Community Trust
Multi Account Tweet Feeds by Webline Alternatives
Import Tweets as Posts
import-tweets-as-posts
"Import Tweets as Posts" plugin allows to easily import tweets from user's timeline or search query. It has also flexibility to import …
Allow Multiple Accounts
allow-multiple-accounts
Allow multiple user accounts to be created, registered, and updated having the same email address.
Customize Feeds for Twitter
twitter-tweets
Customize Feeds for Twitter plugin for WordPress. You can use this to display real time Twitter feeds on any where on your website by using shortcode …
WP Twitter Feeds
wp-twitter-feeds
WP Twitter Feeds - A simple widget which lets you add your latest tweets in just a few clicks on your website.
Slim Jetpack
slimjetpack
Slim version of Jetpack unlinked from WordPress.com :) Supercharge your self-hosted wp site even you're NOT WP.COM users.
Multi Account Tweet Feeds by Webline Developer Profile
13 plugins · 5K total installs
How We Detect Multi Account Tweet Feeds by Webline
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multi-account-tweet-feeds-by-webline/admin/assets/js/wli_matf_settings.jsHTML / DOM Fingerprints
matf_wrap[wli-multi-account-tweet-feeds]