Multi Account Tweet Feeds by Webline Security & Risk Analysis

wordpress.org/plugins/multi-account-tweet-feeds-by-webline

A Simple plugin to show latest Tweets from a multiple Twitter accounts in the same sidebar widget,post,page or text widget content.

80 active installs v1.0.7 PHP + WP 3.5+ Updated Feb 2, 2023
multi-account-tweetsmulti-account-twitter-feedsmultiple-accounttweetstwitter-feeds
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Multi Account Tweet Feeds by Webline Safe to Use in 2026?

Generally Safe

Score 85/100

Multi Account Tweet Feeds by Webline has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin "multi-account-tweet-feeds-by-webline" v1.0.7 exhibits a mixed security posture. On the positive side, it boasts a clean vulnerability history with no known CVEs, suggesting a history of secure development or diligent patching. The code analysis reveals a strong adherence to secure database practices with all SQL queries using prepared statements. Furthermore, the absence of critical taint analysis findings and dangerous functions is encouraging.

However, several areas raise concerns. The plugin has a notable lack of security checks, with zero nonce checks and zero capability checks across its entry points. While the attack surface is small (one shortcode), its lack of protective measures means any discovered vulnerability could be easily exploitable. The output escaping is also a significant weakness, with less than half of the outputs properly escaped, creating a risk of Cross-Site Scripting (XSS) vulnerabilities. The single file operation and external HTTP request, while not inherently problematic, become higher risk due to the absence of input validation and sanitization that is not detailed in this analysis.

In conclusion, while the plugin avoids common and severe vulnerabilities like SQL injection and has a clean history, the lack of authentication and authorization checks, coupled with poor output escaping, presents a substantial risk of XSS and potential privilege escalation if further weaknesses are present but not revealed in this static analysis. The absence of taint analysis flow data also leaves a gap in understanding potential complex exploit chains.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Low output escaping rate
Vulnerabilities
None known

Multi Account Tweet Feeds by Webline Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Multi Account Tweet Feeds by Webline Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
48
44 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

48% escaped92 total outputs
Attack Surface

Multi Account Tweet Feeds by Webline Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wli-multi-account-tweet-feeds] public\multi-account-tweet-feeds-shortcode.php:76
WordPress Hooks 6
actionadmin_menuadmin\multi-account-tweet-feeds-settings.php:11
actionadmin_initadmin\multi-account-tweet-feeds-settings.php:12
actionadmin_enqueue_scriptsadmin\multi-account-tweet-feeds-settings.php:13
actionwp_enqueue_scriptspublic\hook.php:7
actionload-widgets.phppublic\multi-account-tweet-feeds.php:46
actionwidgets_initpublic\multi-account-tweet-feeds.php:416
Maintenance & Trust

Multi Account Tweet Feeds by Webline Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 2, 2023
PHP min version
Downloads6K

Community Trust

Rating66/100
Number of ratings3
Active installs80
Developer Profile

Multi Account Tweet Feeds by Webline Developer Profile

WeblineIndia

13 plugins · 5K total installs

82
trust score
Avg Security Score
91/100
Avg Patch Time
54 days
View full developer profile
Detection Fingerprints

How We Detect Multi Account Tweet Feeds by Webline

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/multi-account-tweet-feeds-by-webline/admin/assets/js/wli_matf_settings.js

HTML / DOM Fingerprints

CSS Classes
matf_wrap
Shortcode Output
[wli-multi-account-tweet-feeds]
FAQ

Frequently Asked Questions about Multi Account Tweet Feeds by Webline