StreamWeasels Twitch Widget Security & Risk Analysis

wordpress.org/plugins/streamweasels-twitch-widget

StreamWeasels Twitch widget.

0 active installs v1.0.0 PHP + WP + Updated Unknown
widget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is StreamWeasels Twitch Widget Safe to Use in 2026?

Generally Safe

Score 100/100

StreamWeasels Twitch Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The static analysis of the "streamweasels-twitch-widget" plugin v1.0.0 indicates a generally strong security posture with no immediately apparent critical vulnerabilities in its attack surface or code signals. The absence of AJAX handlers, REST API routes, shortcodes, cron events, dangerous functions, raw SQL queries, file operations, and external HTTP requests significantly limits the plugin's potential attack vectors. Furthermore, the high percentage of properly escaped output suggests good practices for preventing cross-site scripting (XSS) vulnerabilities.

However, the complete lack of identified taint flows, while seemingly positive, could also indicate an insufficient or incomplete taint analysis process, or that the plugin's functionality is so basic that it doesn't involve user-supplied data in sensitive operations. The absence of nonce checks and capability checks, combined with zero entry points requiring authentication, suggests that the plugin might be designed for public, read-only access, which inherently reduces certain types of risks. Nevertheless, even read-only interfaces can have subtle vulnerabilities if not properly sanitized.

The plugin's vulnerability history is completely clean, with no recorded CVEs. This is a significant strength, suggesting a history of secure development or effective patching. Coupled with the static analysis findings, this plugin appears to be a low-risk option based on the provided data. The primary area for potential concern, though not explicitly indicated as a flaw here, would be any future development that introduces more complex interactions or user input handling without a corresponding increase in security checks.

Vulnerabilities
None known

StreamWeasels Twitch Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

StreamWeasels Twitch Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
48 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped50 total outputs
Attack Surface

StreamWeasels Twitch Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedincludes\class-streamweasels-twitch-widget.php:142
actionadmin_enqueue_scriptsincludes\class-streamweasels-twitch-widget.php:157
actionadmin_enqueue_scriptsincludes\class-streamweasels-twitch-widget.php:158
actionwidgets_initincludes\class-streamweasels-twitch-widget.php:159
actionwp_enqueue_scriptsincludes\class-streamweasels-twitch-widget.php:174
actionwp_enqueue_scriptsincludes\class-streamweasels-twitch-widget.php:175
Maintenance & Trust

StreamWeasels Twitch Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedUnknown
PHP min version
Downloads628

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

StreamWeasels Twitch Widget Developer Profile

StreamWeasels

4 plugins · 2K total installs

98
trust score
Avg Security Score
97/100
Avg Patch Time
2 days
View full developer profile
Detection Fingerprints

How We Detect StreamWeasels Twitch Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/streamweasels-twitch-widget/public/css/streamweasels-twitch-widget-public.css/wp-content/plugins/streamweasels-twitch-widget/public/js/streamweasels-twitch-widget-public.js
Script Paths
/wp-content/plugins/streamweasels-twitch-widget/public/js/streamweasels-twitch-widget-public.js
Version Parameters
streamweasels-twitch-widget/public/css/streamweasels-twitch-widget-public.css?ver=streamweasels-twitch-widget/public/js/streamweasels-twitch-widget-public.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about StreamWeasels Twitch Widget