
Schedule Tweets – TweetBoost Free Security & Risk Analysis
wordpress.org/plugins/tweetboostQuickly schedule tweets from within the post edit screen. Visualize your Twitter schedule in a beautiful dashboard calendar widget.
Is Schedule Tweets – TweetBoost Free Safe to Use in 2026?
Generally Safe
Score 85/100Schedule Tweets – TweetBoost Free has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tweetboost" v1.1.0 plugin exhibits a mixed security posture. On the positive side, it shows a strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and having no recorded historical vulnerabilities or critical taint flows. The absence of dangerous functions, file operations, and external HTTP requests is also commendable. However, a significant concern arises from its attack surface. With 6 AJAX handlers, 4 of which lack authentication checks, there's a substantial risk of unauthorized actions being performed by unauthenticated users.
The limited output escaping (only 24% properly escaped) further exacerbates this risk, as it opens the door for cross-site scripting (XSS) vulnerabilities, especially when combined with unprotected AJAX endpoints. While nonce checks and capability checks are present, their application is insufficient to cover all the identified unprotected AJAX handlers. The vulnerability history being clean is a positive indicator, suggesting a potentially well-maintained codebase or limited exposure, but it does not mitigate the immediate risks identified in the static analysis.
In conclusion, "tweetboost" v1.1.0 has strengths in its database interaction and lack of historical issues. Nevertheless, the significant number of unprotected AJAX handlers and poor output escaping create a considerable security risk that requires immediate attention. The plugin has a strong foundation in some areas but overlooks crucial security mechanisms for its primary entry points.
Key Concerns
- Unprotected AJAX handlers
- Low output escaping coverage
- Bundled Select2 library
Schedule Tweets – TweetBoost Free Security Vulnerabilities
Schedule Tweets – TweetBoost Free Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Schedule Tweets – TweetBoost Free Attack Surface
AJAX Handlers 6
WordPress Hooks 21
Scheduled Events 1
Maintenance & Trust
Schedule Tweets – TweetBoost Free Maintenance & Trust
Maintenance Signals
Community Trust
Schedule Tweets – TweetBoost Free Alternatives
Customize Feeds for Twitter
twitter-tweets
Customize Feeds for Twitter plugin for WordPress. You can use this to display real time Twitter feeds on any where on your website by using shortcode …
Slim Jetpack
slimjetpack
Slim version of Jetpack unlinked from WordPress.com :) Supercharge your self-hosted wp site even you're NOT WP.COM users.
Display Tweets
display-tweets-php
Display Tweets is an easy to use, future proof Twitter feed plugin that uses PHP to make requests to the v1.1 Twitter REST API.
Peadig's Twitter Feed: Embedded Timeline WordPress Plugin
wp-twitter-feed
A simple Twitter feed that outputs your latest tweets in HTML into any post, page, template or sidebar widget. Customisable and easy to install!
Twiget Twitter Widget
twiget
A widget to display the latest Twitter status updates.
Schedule Tweets – TweetBoost Free Developer Profile
3 plugins · 30 total installs
How We Detect Schedule Tweets – TweetBoost Free
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tweetboost/css/admin-style.css/wp-content/plugins/tweetboost/css/calendar.css/wp-content/plugins/tweetboost/js/admin.js/wp-content/plugins/tweetboost/js/calendar.js/wp-content/plugins/tweetboost/js/tweet-boost-admin.js/wp-content/plugins/tweetboost/js/admin.js/wp-content/plugins/tweetboost/js/calendar.js/wp-content/plugins/tweetboost/js/tweet-boost-admin.jstweetboost/css/admin-style.css?ver=tweetboost/css/calendar.css?ver=tweetboost/js/admin.js?ver=tweetboost/js/calendar.js?ver=tweetboost/js/tweet-boost-admin.js?ver=HTML / DOM Fingerprints
tb-tab-activedata-tab-idTweetBoosttbtweetBoost