responsive-twitter-widget Security & Risk Analysis

wordpress.org/plugins/responsive-twitter-widget

Responsive twitter widget will be shown very smoothly. It is very easy to setup . We can go to widget and drag drop .

100 active installs v1.0 PHP + WP 3.5+ Updated Dec 24, 2015
twitter-bytwitter-followtwitter-follow-buttontwitter-like-button
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is responsive-twitter-widget Safe to Use in 2026?

Generally Safe

Score 85/100

responsive-twitter-widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "responsive-twitter-widget" plugin version 1.0 exhibits a generally strong security posture based on the provided static analysis. The complete absence of known CVEs and a zero-day vulnerability history suggests a well-maintained and secure codebase over time. Furthermore, the plugin demonstrates good practices by having no detectable attack surface through AJAX, REST API, shortcodes, or cron events. It also avoids dangerous functions, file operations, and external HTTP requests. The use of prepared statements for all SQL queries is a significant strength, mitigating SQL injection risks.

However, the static analysis does reveal a notable concern: only 16% of output is properly escaped. This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data displayed within the widget, if not adequately sanitized or escaped before rendering, could be exploited by attackers to inject malicious scripts. Given the lack of taint analysis data, it's impossible to quantify the exact risk of these unescaped outputs, but it remains the primary security weakness identified.

In conclusion, the plugin is strong in areas like input handling and avoiding common attack vectors. The lack of past vulnerabilities is a positive indicator. The critical weakness lies in output escaping. While the attack surface is minimal, the potential for XSS due to insufficient output escaping warrants attention. Addressing this issue would significantly improve the plugin's overall security.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

responsive-twitter-widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

responsive-twitter-widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

16% escaped31 total outputs
Attack Surface

responsive-twitter-widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwidgets_inittwitter-widget.php:19
actionwp_enqueue_scriptstwitter-widget.php:100
Maintenance & Trust

responsive-twitter-widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedDec 24, 2015
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

responsive-twitter-widget Developer Profile

engrmostafijur

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect responsive-twitter-widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/responsive-twitter-widget/css/feeds_style.css
Script Paths
https://platform.twitter.com/widgets.js

HTML / DOM Fingerprints

CSS Classes
twitter-wrappertwitter-rowpix-twitter-widgetpix-title
HTML Comments
<!-- Text Input --><!-- Show Widget Title --><!-- Show Twitter Username --><!-- Show Twitter Widget ID -->+2 more
Data Attributes
data-widget-id
JS Globals
twitter-wjs
FAQ

Frequently Asked Questions about responsive-twitter-widget