
Tumblr Widget Security & Risk Analysis
wordpress.org/plugins/tumblr-widget-for-wordpressAllows you to import a Tumblr into any widgetized area of a WordPress blog.
Is Tumblr Widget Safe to Use in 2026?
Generally Safe
Score 85/100Tumblr Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The tumblr-widget-for-wordpress plugin v2.1 exhibits a mixed security posture. On one hand, the absence of known vulnerabilities, SQL injection risks through prepared statements, and no reported external HTTP requests or file operations are positive indicators. The lack of any taint analysis findings also suggests that basic data flow security might be present.
However, significant concerns arise from the static analysis. The plugin uses the deprecated `create_function` function, which is a known security risk as it allows for the execution of arbitrary code. Furthermore, a concerningly low percentage of output is properly escaped (1%), indicating a high likelihood of cross-site scripting (XSS) vulnerabilities. The complete lack of nonce and capability checks on its entry points (if any were present and identified) also points to potential authorization and CSRF issues if the plugin were to have any interactive elements beyond what is reported.
Given the lack of reported historical vulnerabilities, it's difficult to infer long-term trends. However, the presence of `create_function` and the extremely poor output escaping are significant red flags that outweigh the positive aspects. While the plugin might appear clean due to no known CVEs, the identified code-level weaknesses present substantial risks that could be exploited.
Key Concerns
- Uses deprecated and dangerous create_function
- Extremely low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
Tumblr Widget Security Vulnerabilities
Tumblr Widget Code Analysis
Dangerous Functions Found
Output Escaping
Tumblr Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Tumblr Widget Maintenance & Trust
Maintenance Signals
Community Trust
Tumblr Widget Alternatives
F2 Tumblr Widget
f2-tumblr-widget
This widget displays recent posts from a tumblr blog.
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Tumblr Widget Developer Profile
1 plugin · 400 total installs
How We Detect Tumblr Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
tumblr_postid_base="tumblr-widget"