
TP – TweetPress Security & Risk Analysis
wordpress.org/plugins/tpAll the tools you need to integrate your wordpress and twitter.
Is TP – TweetPress Safe to Use in 2026?
Generally Safe
Score 85/100TP – TweetPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'tp' v1.4 presents a mixed security posture. While it demonstrates good practices in its handling of SQL queries, utilizing prepared statements for all queries and performing a reasonable number of capability checks, there are significant areas of concern. The presence of two AJAX handlers without authentication checks creates a direct attack vector. Furthermore, only 12% of outputs are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the absence of critical or high-severity taint flows which might otherwise catch such issues. The plugin also utilizes the deprecated and insecure `create_function` function twice. Encouragingly, the plugin has no recorded vulnerability history, suggesting a generally stable past. However, the current static analysis findings, particularly the unprotected entry points and poor output escaping, introduce notable risks that outweigh the positive aspects.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- Use of dangerous function: create_function
TP – TweetPress Security Vulnerabilities
TP – TweetPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
TP – TweetPress Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 43
Maintenance & Trust
TP – TweetPress Maintenance & Trust
Maintenance Signals
Community Trust
TP – TweetPress Alternatives
Postmatic Social Commenting
postmatic-social-commenting
A tiny, fast, and convenient way to let your readers comment using their social profiles.
Tweets Widget
tweets-widget
Tweets Widget compatible with the new Twitter API 1.1
U-Tweets
u-tweets
U-Tweets is a simple to use WordPress Plugin powered with Twitter OAuth API to display tweets.
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
OpenID Connect Generic Client
daggerhart-openid-connect-generic
A simple client that provides SSO or opt-in authentication against a generic OAuth2 Server implementation.
TP – TweetPress Developer Profile
7 plugins · 8K total installs
How We Detect TP – TweetPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tp/css/tweetpress.css/wp-content/plugins/tp/js/tweetpress.js/wp-content/plugins/tp/js/tweetpress.jstp/style.css?ver=tp/script.js?ver=HTML / DOM Fingerprints
tweetpress-widget-containertweetpress-tweet-bodytweetpress-tweet-metatp_tweet_buttontp_share_button<!-- TweetPress widget starts --><!-- TweetPress widget ends --><!-- If you like this plugin, Follow me @l0uy for more updates. -->data-tweet-urldata-tweet-textdata-tweet-viatweetpressTP_AJAX_URL[tweetpress_feed][tweetpress_timeline][tweetpress_buttons]