
Social Media Pack – Twitter Module Security & Risk Analysis
wordpress.org/plugins/smp-twitter-module-oauthThe social media pack automatically sends your wordpress posts onto twitter
Is Social Media Pack – Twitter Module Safe to Use in 2026?
Generally Safe
Score 85/100Social Media Pack – Twitter Module has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The smp-twitter-module-oauth plugin version 1.2 presents a mixed security posture. While it boasts a zero-attack surface in terms of exposed AJAX handlers, REST API routes, shortcodes, and cron events, which is a significant positive, several concerning code signals and taint analysis results indicate potential weaknesses.
The presence of the `unserialize` function, a known dangerous function, is a critical concern. This, coupled with a high-severity taint flow with an unsanitized path, strongly suggests a potential for remote code execution or other severe vulnerabilities if an attacker can control the data being unserialized or passed through the unsanitized path. Furthermore, the lack of output escaping on all identified outputs is a major vulnerability, opening the door to cross-site scripting (XSS) attacks.
The plugin has a clean vulnerability history with no recorded CVEs. This is a good sign, suggesting that the developers have either been diligent in past development or the plugin has not been a significant target for exploitation. However, the lack of known vulnerabilities does not negate the risks identified in the static and taint analysis, which highlight inherent dangers within the current codebase. The complete absence of nonce checks and a single capability check are also areas of concern, especially given the potential for insecure function usage.
In conclusion, while the plugin's minimal attack surface is commendable, the critical risks associated with `unserialize`, unsanitized taint flows, and lack of output escaping cannot be overlooked. The absence of known vulnerabilities is a positive but should not lead to complacency given these internal code weaknesses. Developers should prioritize addressing these identified issues.
Key Concerns
- Dangerous function 'unserialize' present
- High severity taint flow with unsanitized path
- Output escaping not properly implemented (0%)
- No nonce checks
- Only 1 capability check found
- SQL queries with potential for injection (40% prepared)
Social Media Pack – Twitter Module Security Vulnerabilities
Social Media Pack – Twitter Module Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Social Media Pack – Twitter Module Attack Surface
WordPress Hooks 2
Maintenance & Trust
Social Media Pack – Twitter Module Maintenance & Trust
Maintenance Signals
Community Trust
Social Media Pack – Twitter Module Alternatives
No alternatives data available yet.
Social Media Pack – Twitter Module Developer Profile
1 plugin · 10 total installs
How We Detect Social Media Pack – Twitter Module
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smp-twitter-module-oauth/twitterFramework/twitteroauth.phpHTML / DOM Fingerprints
<!--
window.location = "window.location