
ST Twitter Security & Risk Analysis
wordpress.org/plugins/st-twitter-wpST Twitter is a plugin that offers you the possibility to show your lastest tweet in your WordPress web site
Is ST Twitter Safe to Use in 2026?
Generally Safe
Score 85/100ST Twitter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "st-twitter-wp" v1.0.1 plugin exhibits a mixed security posture. On the positive side, it has a very small attack surface, with only one shortcode and no unprotected entry points identified in the static analysis. The absence of known CVEs and a clean vulnerability history are also strong indicators of a relatively secure past. Furthermore, all SQL queries are prepared, which is a significant security strength against SQL injection vulnerabilities.
However, several concerning code signals warrant attention. The presence of dangerous functions like `shell_exec` and `create_function` indicates a potential for severe code execution vulnerabilities if not handled with extreme caution and robust input sanitization. The low percentage (22%) of properly escaped outputs is a significant risk, suggesting a high likelihood of Cross-Site Scripting (XSS) vulnerabilities across many output points. The absence of nonce checks on the identified entry points, combined with limited capability checks, further amplifies the risk of unauthorized actions or privilege escalation. While the taint analysis did not reveal critical or high-severity unsanitized paths, the single flow with an unsanitized path and the reliance on potentially risky functions still present a latent threat.
In conclusion, while the plugin benefits from a small attack surface and a lack of historical vulnerabilities, the identified code signals related to dangerous functions, insufficient output escaping, and missing security checks on entry points introduce notable risks. Developers should prioritize addressing these specific code-level concerns to improve the plugin's overall security.
Key Concerns
- Dangerous functions present (shell_exec, create_function)
- Low percentage of properly escaped outputs
- No nonce checks on entry points
- Taint flow with unsanitized path
- Limited capability checks
ST Twitter Security Vulnerabilities
ST Twitter Release Timeline
ST Twitter Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
ST Twitter Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
ST Twitter Maintenance & Trust
Maintenance Signals
Community Trust
ST Twitter Alternatives
Click To Tweet
click-to-tweet-by-todaymade
This plugin allows you to create beautiful Click To Tweet boxes anywhere in your blog post.
Easy Pull Quotes
easy-pull-quotes
Easily add tweetable pull quotes to your posts.
Custom twitter widget pro
custom-twitter-widget-pro
Display twitter feeds on your WordPress site by using the Twitter feed widget pro plugin.
Another Twitter Plugin
another-twitter-extension
Twitter plugin for developers, plugin that you want and need, fully customizable style, works with multiple hashtags or usernames and you are not limi …
The Advanced Twitter Plugin
advanced-twitter
Fully customize tweets that readers share using your Tweet button.
ST Twitter Developer Profile
2 plugins · 20 total installs
How We Detect ST Twitter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/st-twitter-wp/editor_button/editor_plugin.js/wp-content/plugins/st-twitter-wp/editor_button/tiny_mce_popup.js/wp-content/plugins/st-twitter-wp/editor_button/button.js/wp-content/plugins/st-twitter-wp/css/style.css/wp-content/plugins/st-twitter-wp/js/custom.js/wp-content/plugins/st-twitter-wp/tmh/tmhOAuth.php/wp-content/plugins/st-twitter-wp/tmh/tmhUtilities.php/wp-content/plugins/st-twitter-wp/editor_button/editor_plugin.js/wp-content/plugins/st-twitter-wp/editor_button/tiny_mce_popup.js/wp-content/plugins/st-twitter-wp/editor_button/button.js/wp-content/plugins/st-twitter-wp/js/custom.jsHTML / DOM Fingerprints
st-twitter-adminst_load_rssz-labeldata-plugin="st-twitter-wp"st_twitter_wpst_Twitter_wp[st_twitter_web][st_twitter_followers]