
Stylish Twitter Profile Box Security & Risk Analysis
wordpress.org/plugins/stylish-twitter-profile-boxAdds a stylish and responsive twitter profile box .
Is Stylish Twitter Profile Box Safe to Use in 2026?
Generally Safe
Score 85/100Stylish Twitter Profile Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "stylish-twitter-profile-box" plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and reports no known vulnerabilities or CVEs. The absence of file operations and external HTTP requests, along with a clean taint analysis, further strengthens its security profile. However, significant concerns arise from the code signals. The presence of the `create_function` function, known for its security implications due to its dynamic code execution capabilities, is a notable weakness. Additionally, the lack of nonce checks and capability checks on potential entry points, though currently limited in number (zero entry points detected), presents a future risk if the plugin's functionality expands or if any entry points are inadvertently introduced without proper authorization mechanisms. While the plugin currently has a clean vulnerability history, this does not negate the inherent risks posed by insecure coding practices.
In conclusion, the plugin has some strong security foundations, particularly in data handling and the absence of past vulnerabilities. Nevertheless, the reliance on `create_function` and the complete absence of authorization checks are critical red flags that significantly elevate the potential risk. A thorough code review focusing on how `create_function` is used and ensuring all new or existing functionalities are appropriately secured with nonces and capability checks is highly recommended. The current lack of exploitable vulnerabilities is encouraging, but the identified code signals represent a potential attack vector that needs immediate attention.
Key Concerns
- Use of dangerous function: create_function
- Missing nonce checks
- Missing capability checks
- Output escaping below 100%
Stylish Twitter Profile Box Security Vulnerabilities
Stylish Twitter Profile Box Code Analysis
Dangerous Functions Found
Output Escaping
Stylish Twitter Profile Box Attack Surface
WordPress Hooks 4
Maintenance & Trust
Stylish Twitter Profile Box Maintenance & Trust
Maintenance Signals
Community Trust
Stylish Twitter Profile Box Alternatives
Astra Widgets
astra-widgets
Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.
ProfileGrid – User Profiles, Groups and Communities
profilegrid-user-profiles-groups-and-communities
Custom user profiles plugin ❤ with paid memberships, groups, communities, content restriction, user registration, messaging, WooCommerce memberships, …
Easy Profile Widget
easy-profile-widget
Display User Profile Section with Gravatar on your sidebar widgets easily.
Pinterest Widget by Angie Makes
wpc-pinterest-widget
Add official Pinterest widget to your site. Insert your Pinterest board widget, profile widget, and pin widget to any widget area.
BuddyPress User Info Widget
bp-profile-widget-for-blogs
BuddyPress User Info Widget allows easy listing of user profile info in the widget area.
Stylish Twitter Profile Box Developer Profile
1 plugin · 10 total installs
How We Detect Stylish Twitter Profile Box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stylish-twitter-profile-box/css/stpb-main.cssstylish-twitter-profile-box/css/stpb-main.css?ver=HTML / DOM Fingerprints
stpb-twitter-profile-box<!--[if gte IE 9]>