Ozh' Tweet Archiver Security & Risk Analysis

wordpress.org/plugins/ozh-tweet-archiver

Import and archive your tweets with WordPress

40 active installs v2.0.4 PHP + WP 3.0+ Updated Jun 14, 2015
archiveimportozhtweetstwitter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ozh' Tweet Archiver Safe to Use in 2026?

Generally Safe

Score 85/100

Ozh' Tweet Archiver has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The ozh-tweet-archiver v2.0.4 plugin presents a generally positive security posture based on the provided static analysis and vulnerability history. The absence of identified CVEs, coupled with a lack of critical or high-severity issues in taint analysis, suggests a well-maintained codebase. The attack surface is minimal, with no unprotected entry points across AJAX handlers, REST API routes, or shortcodes. However, there are areas for improvement. The relatively low percentage of properly escaped output (24%) is a concern, as it indicates a higher risk of cross-site scripting (XSS) vulnerabilities, particularly if user-supplied data is not consistently sanitized before being displayed. Furthermore, the usage of raw SQL queries for 75% of the queries presents a risk of SQL injection if not handled with extreme care, although the absence of taint flows with unsanitized paths somewhat mitigates this immediate concern.

While the plugin demonstrates strengths in its limited attack surface and clean vulnerability history, the identified code signals regarding output escaping and SQL query preparedness warrant attention. The lack of capability checks on any entry points is a notable weakness that could be exploited if any vulnerabilities were to be introduced in the future. Overall, ozh-tweet-archiver v2.0.4 is relatively secure but could benefit from increased attention to output sanitization and the adoption of prepared statements for all SQL queries to further harden its security.

Key Concerns

  • Low percentage of properly escaped output
  • High percentage of SQL queries not using prepared statements
  • No capability checks on entry points
Vulnerabilities
None known

Ozh' Tweet Archiver Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ozh' Tweet Archiver Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
2 prepared
Unescaped Output
52
16 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

25% prepared8 total queries

Output Escaping

24% escaped68 total outputs
Attack Surface

Ozh' Tweet Archiver Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
actionozh_ta_sourceinc\template_tags.php:15
actionozh_ta_idinc\template_tags.php:24
actionozh_ta_tweet_linkinc\template_tags.php:34
actionozh_ta_reply_to_nameinc\template_tags.php:43
actionozh_ta_reply_to_tweetinc\template_tags.php:52
actionozh_ta_is_reply_or_notinc\template_tags.php:61
actionozh_ta_is_retweet_or_notinc\template_tags.php:70
actionozh_ta_in_reply_to_tweetinc\template_tags.php:87
actionozh_ta_total_tweetsinc\template_tags.php:96
actionozh_ta_total_followersinc\template_tags.php:105
actionozh_ta_total_followinginc\template_tags.php:114
actionozh_ta_total_listedinc\template_tags.php:123
actionozh_ta_tweeting_sinceinc\template_tags.php:132
actionozh_ta_twitter_avatarinc\template_tags.php:142
actionozh_ta_total_linksinc\template_tags.php:151
actionozh_ta_link_ratioinc\template_tags.php:162
actionozh_ta_reply_ratioinc\template_tags.php:173
actionozh_ta_total_repliesinc\template_tags.php:183
actionozh_ta_total_replies_uniquesinc\template_tags.php:193
actionozh_ta_total_archivedinc\template_tags.php:202
actionozh_ta_cron_importozh-ta.php:51
actioninitozh-ta.php:54
actionadmin_initozh-ta.php:55
actionadmin_menuozh-ta.php:56
filterthe_contentozh-ta.php:57
actionadmin_noticesozh-ta.php:88
filterplugin_row_metaozh-ta.php:90

Scheduled Events 1

ozh_ta_cron_import
Maintenance & Trust

Ozh' Tweet Archiver Maintenance & Trust

Maintenance Signals

WordPress version tested9.9
Last updatedJun 14, 2015
PHP min version
Downloads10K

Community Trust

Rating84/100
Number of ratings6
Active installs40
Developer Profile

Ozh' Tweet Archiver Developer Profile

Ozh

27 plugins · 5K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ozh' Tweet Archiver

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ozh-tweet-archiver/inc/utils.php/wp-content/plugins/ozh-tweet-archiver/inc/template_tags.php/wp-content/plugins/ozh-tweet-archiver/inc/settings.php/wp-content/plugins/ozh-tweet-archiver/inc/option-page.php/wp-content/plugins/ozh-tweet-archiver/inc/import.php

HTML / DOM Fingerprints

CSS Classes
linkusernamehashtag
HTML Comments
Known bug:HistoryFIXME Known bug:Constants that should work for everyone+3 more
Data Attributes
data-screen_name
JS Globals
ozh_ta
FAQ

Frequently Asked Questions about Ozh' Tweet Archiver