Twitter API Master – Twitter Widgets For WordPress Security & Risk Analysis

wordpress.org/plugins/teg-twitter-api

Post to twitter, twitter feeds, twitter trends shortcode and widget wordpres plugin.

50 active installs v1.2.5 PHP + WP 4.5+ Updated Jan 26, 2018
apisettingsshortcodetwitterwidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Twitter API Master – Twitter Widgets For WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Twitter API Master – Twitter Widgets For WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "teg-twitter-api" v1.2.5 plugin exhibits a generally good security posture based on the provided static analysis. The absence of any detected CVEs in its history is a strong positive indicator. Furthermore, the lack of untainted flows, dangerous functions, and raw SQL queries demonstrates a commitment to secure coding practices. The majority of output is properly escaped, and the presence of nonce and capability checks, along with prepared statements for SQL, further bolsters its security. However, a few areas warrant attention. The presence of file operations and external HTTP requests, while not inherently insecure, can sometimes be vectors for vulnerabilities if not handled with extreme care and proper sanitization. The limited number of analysis points for taint flows suggests that the analysis might not have been exhaustive, and that deeper inspection might be warranted.

While the plugin appears to be well-secured at present, with no known vulnerabilities or critical issues flagged in the static analysis, the potential for risk exists in the areas of file operations and external requests. These functionalities, even when used correctly, can introduce attack vectors. The lack of any prior vulnerability history is a significant strength, suggesting diligent maintenance and security awareness. However, a truly exhaustive security analysis would ideally involve more extensive taint analysis and manual code review of the file operations and external HTTP requests. Overall, the plugin presents a low immediate risk, but continuous vigilance and review of these specific code paths are recommended.

Key Concerns

  • External HTTP requests present potential risks
  • File operations present potential risks
  • Output escaping is not 100% proper
  • Limited taint flow analysis performed
Vulnerabilities
None known

Twitter API Master – Twitter Widgets For WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Twitter API Master – Twitter Widgets For WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
78
283 escaped
Nonce Checks
2
Capability Checks
1
File Operations
3
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

78% escaped361 total outputs
Attack Surface

Twitter API Master – Twitter Widgets For WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 38
actionsave_postincludes\abstracts\abstract-teg-ta-widget.php:64
actiondeleted_postincludes\abstracts\abstract-teg-ta-widget.php:65
actionswitch_themeincludes\abstracts\abstract-teg-ta-widget.php:66
actionadmin_enqueue_scriptsincludes\admin\class-teg-ta-admin-assets.php:45
actionadmin_enqueue_scriptsincludes\admin\class-teg-ta-admin-assets.php:46
actionadmin_menuincludes\admin\class-teg-ta-admin-menus.php:29
actionload-post.phpincludes\admin\class-teg-ta-admin-meta-boxes.php:31
actionload-post-new.phpincludes\admin\class-teg-ta-admin-meta-boxes.php:33
actionadd_meta_boxesincludes\admin\class-teg-ta-admin-meta-boxes.php:50
actionsave_postincludes\admin\class-teg-ta-admin-meta-boxes.php:52
actionadmin_noticesincludes\admin\class-teg-ta-admin-meta-boxes.php:54
actioninitincludes\admin\class-teg-ta-admin.php:28
filterteg_twitter_api_settings_tabs_arrayincludes\admin\settings\class-teg-ta-settings-api.php:32
filterteg_twitter_api_settings_tabs_arrayincludes\admin\settings\class-teg-ta-settings-general.php:30
filterteg_twitter_api_settings_tabs_arrayincludes\admin\settings\class-teg-ta-settings-layouts.php:32
filterteg_twitter_api_settings_tabs_arrayincludes\admin\settings\class-teg-ta-settings-page.php:40
actionteg_ta_twitter_trend_shortcode_layout_afterincludes\api\twitter\class-teg-ta-api-places.php:88
actionteg_ta_twitter_trend_widget_layout_afterincludes\api\twitter\class-teg-ta-api-places.php:90
actionteg_ta_twitter_trend_shortcode_layout_afterincludes\api\twitter\class-teg-ta-api-twitter-trends.php:88
actionteg_ta_twitter_trend_widget_layout_afterincludes\api\twitter\class-teg-ta-api-twitter-trends.php:90
actionteg_ta_twitter_feed_shortcode_layout_afterincludes\api\twitter\class-teg-ta-api-twitter-tweets.php:58
actionteg_ta_twitter_feed_widget_layout_afterincludes\api\twitter\class-teg-ta-api-twitter-tweets.php:60
actionwp_enqueue_scriptsincludes\class-teg-ta-frontend-scripts.php:45
actionwp_print_scriptsincludes\class-teg-ta-frontend-scripts.php:46
actionwp_print_footer_scriptsincludes\class-teg-ta-frontend-scripts.php:47
actioninitincludes\class-teg-ta-install.php:32
actionadmin_initincludes\class-teg-ta-install.php:33
actioninitincludes\class-teg-ta-query.php:36
actionwp_loadedincludes\class-teg-ta-query.php:38
filterquery_varsincludes\class-teg-ta-query.php:39
actionparse_requestincludes\class-teg-ta-query.php:40
actionpre_get_postsincludes\class-teg-ta-query.php:41
filterredirect_canonicalincludes\class-teg-ta-query.php:214
actionwidgets_initincludes\teg-ta-widget-functions.php:38
actionafter_setup_themeteg-twitter-api.php:120
actionafter_setup_themeteg-twitter-api.php:121
actioninitteg-twitter-api.php:122
actioninitteg-twitter-api.php:123

Scheduled Events 1

teg_twitter_api_flush_rewrite_rules
Maintenance & Trust

Twitter API Master – Twitter Widgets For WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 26, 2018
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs50
Developer Profile

Twitter API Master – Twitter Widgets For WordPress Developer Profile

Theme Egg

5 plugins · 200 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Twitter API Master – Twitter Widgets For WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/teg-twitter-api/assets/css/style.css/wp-content/plugins/teg-twitter-api/assets/js/teg-twitter-api.js/wp-content/plugins/teg-twitter-api/assets/js/owl.carousel.min.js/wp-content/plugins/teg-twitter-api/assets/js/isotope.js/wp-content/plugins/teg-twitter-api/assets/css/owl.carousel.css/wp-content/plugins/teg-twitter-api/assets/css/owl.theme.css/wp-content/plugins/teg-twitter-api/assets/css/magnific-popup.css
Script Paths
/wp-content/plugins/teg-twitter-api/assets/js/teg-twitter-api.js/wp-content/plugins/teg-twitter-api/assets/js/owl.carousel.min.js/wp-content/plugins/teg-twitter-api/assets/js/isotope.js
Version Parameters
/wp-content/plugins/teg-twitter-api/assets/css/style.css?ver=/wp-content/plugins/teg-twitter-api/assets/js/teg-twitter-api.js?ver=/wp-content/plugins/teg-twitter-api/assets/js/owl.carousel.min.js?ver=/wp-content/plugins/teg-twitter-api/assets/js/isotope.js?ver=/wp-content/plugins/teg-twitter-api/assets/css/owl.carousel.css?ver=/wp-content/plugins/teg-twitter-api/assets/css/owl.theme.css?ver=/wp-content/plugins/teg-twitter-api/assets/css/magnific-popup.css?ver=

HTML / DOM Fingerprints

CSS Classes
teg-twitter-api-wrapperteg-twitter-feed
Data Attributes
data-plugin-name="teg-twitter-api"
JS Globals
TEG_Twitter_API_Settings
Shortcode Output
[teg_twitter_feed][teg_twitter_followers]
FAQ

Frequently Asked Questions about Twitter API Master – Twitter Widgets For WordPress