
showTweets Security & Risk Analysis
wordpress.org/plugins/showtweetsRetrieve mulitple status updates from multiple Twitter accounts and display on your blog.
Is showTweets Safe to Use in 2026?
Generally Safe
Score 85/100showTweets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "showtweets" v0.2 plugin exhibits a mixed security posture. On the positive side, it boasts a zero attack surface in terms of direct entry points like AJAX handlers, REST API routes, and shortcodes, and it has no known past vulnerabilities. Furthermore, all SQL queries are properly prepared, and there are no file operations or bundled libraries to consider. This indicates a diligent effort to avoid common plugin pitfalls.
However, significant concerns arise from the output escaping and taint analysis. The fact that 100% of the identified outputs are not properly escaped is a critical vulnerability. This means any data displayed to users, particularly if it originates from external sources or user input, could be manipulated to execute malicious scripts (XSS). Coupled with this, the taint analysis reveals two flows with unsanitized paths, indicating potential avenues for attackers to inject malicious code or manipulate data, even without a large attack surface. The presence of external HTTP requests, while not inherently problematic, warrants careful scrutiny in conjunction with the unescaped output and unsanitized taint flows.
In conclusion, while "showtweets" v0.2 excels in avoiding common entry points and SQL injection risks, the severe lack of output escaping and the presence of unsanitized taint flows represent a substantial security risk. The absence of known vulnerabilities is a positive indicator of development quality, but these identified code weaknesses require immediate attention to prevent potential XSS attacks and data manipulation.
Key Concerns
- 0% of output properly escaped
- 2 flows with unsanitized paths
- 1 external HTTP request
showTweets Security Vulnerabilities
showTweets Release Timeline
showTweets Code Analysis
Output Escaping
Data Flow Analysis
showTweets Attack Surface
WordPress Hooks 1
Maintenance & Trust
showTweets Maintenance & Trust
Maintenance Signals
Community Trust
showTweets Alternatives
Custom Order Status Manager for WooCommerce
bp-custom-order-status-for-woocommerce
Custom Order Status Manager for WooCommerce plugin allows you to create, delete and edit order statuses to better control the flow of your orders.
Ni WooCommerce Custom Order Status
ni-woocommerce-custom-order-status
WC requires at least: 4.0 WC tested up to: 9.7 Last Updated Date: 10-March-2026 WooCommerce Custom Order Status plug-in allows you to create and manag …
Extended Post Status
extended-post-status
This plugin provides the option to add new statuses to the backend and define the system relevant status settings. You can add/edit statuses just as c …
PublishPress Statuses – Custom Post Status and Workflow
publishpress-statuses
The PublishPress Statuses plugin allows you to create additional statuses for your posts. You can use each status to create publishing workflows.
Advanced Custom Order Status for WooCommerce
advanced-custom-order-status-for-woocommerce
Easily create, edit, and delete custom order status in WooCommerce. Add icon, color and action to enhance the visual representation of order statuses.
showTweets Developer Profile
1 plugin · 10 total installs
How We Detect showTweets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapform-tableid="usernames"id="count"id="convert"