Twinfield Security & Risk Analysis

wordpress.org/plugins/twinfield

This plugin makes a connection with the Twinfield adminsitration software.

10 active installs v1.1.0 PHP + WP 3.0+ Updated Jan 2, 2015
administrationtwinfield
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Twinfield Safe to Use in 2026?

Generally Safe

Score 85/100

Twinfield has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The Twinfield plugin v1.1.0 presents a mixed security posture. On one hand, the plugin demonstrates good security practices by utilizing prepared statements for all SQL queries, implementing nonce checks, and performing capability checks on its entry points. The absence of file operations and external HTTP requests further reduces the attack surface. Furthermore, the plugin has no recorded vulnerability history, indicating a potentially stable and secure past.

However, there are significant areas of concern that cannot be overlooked. The static analysis reveals the presence of the `create_function` dangerous function three times, which is a known security risk as it can be exploited for arbitrary code execution if user-supplied data is passed to it without proper sanitization. Additionally, a very low percentage (5%) of output is properly escaped, suggesting a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis shows no flows, this could be due to the limited scope of the analysis or the specific data used, and the identified code signals suggest real risks.

In conclusion, while the plugin has a clean vulnerability history and employs some secure coding practices, the use of `create_function` and the widespread lack of output escaping are critical weaknesses that significantly elevate the risk profile. These issues require immediate attention and remediation to prevent potential security breaches.

Key Concerns

  • Presence of dangerous function create_function
  • Low output escaping percentage
Vulnerabilities
None known

Twinfield Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Twinfield Release Timeline

v1.1.0Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Twinfield Code Analysis

Dangerous Functions
3
Raw SQL Queries
0
1 prepared
Unescaped Output
134
7 escaped
Nonce Checks
3
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functioncreate_function( null, "twinfield_settings_section( 'section-login' );" ),classes\Pronamic\WP\TwinfieldPlugin\Settings.php:36
create_functioncreate_function( null, "twinfield_settings_section( 'section-defaults' );" ),classes\Pronamic\WP\TwinfieldPlugin\Settings.php:78
create_functioncreate_function( null, "twinfield_settings_section( 'section-permalinks' );" ),classes\Pronamic\WP\TwinfieldPlugin\Settings.php:170

SQL Query Safety

100% prepared1 total queries

Output Escaping

5% escaped141 total outputs
Attack Surface

Twinfield Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
actionadd_meta_boxesclasses\Pronamic\WP\Twinfield\Article\ArticleMetaBox.php:33
actionsave_postclasses\Pronamic\WP\Twinfield\Article\ArticleMetaBox.php:35
actiongenerate_rewrite_rulesclasses\Pronamic\WP\Twinfield\Customer\Customer.php:8
actionquery_varsclasses\Pronamic\WP\Twinfield\Customer\Customer.php:9
actiontemplate_redirectclasses\Pronamic\WP\Twinfield\Customer\Customer.php:11
filterwp_titleclasses\Pronamic\WP\Twinfield\Customer\Customer.php:13
actionadd_meta_boxesclasses\Pronamic\WP\Twinfield\Customer\CustomerMetaBox.php:33
actionsave_postclasses\Pronamic\WP\Twinfield\Customer\CustomerMetaBox.php:35
actionadmin_initclasses\Pronamic\WP\Twinfield\FormBuilder\FormBuilder.php:26
actiongenerate_rewrite_rulesclasses\Pronamic\WP\Twinfield\Invoice\Invoice.php:8
actionquery_varsclasses\Pronamic\WP\Twinfield\Invoice\Invoice.php:9
actiontemplate_redirectclasses\Pronamic\WP\Twinfield\Invoice\Invoice.php:11
actionadmin_initclasses\Pronamic\WP\Twinfield\Invoice\Invoice.php:13
actionadd_meta_boxesclasses\Pronamic\WP\Twinfield\Invoice\InvoiceMetaBox.php:42
actionsave_postclasses\Pronamic\WP\Twinfield\Invoice\InvoiceMetaBox.php:44
actionsave_postclasses\Pronamic\WP\Twinfield\Invoice\InvoiceMetaBox.php:45
actionadmin_initclasses\Pronamic\WP\Twinfield\Merge\Merge.php:8
actionadmin_initclasses\Pronamic\WP\Twinfield\Merge\Merge.php:9
actionadmin_initclasses\Pronamic\WP\TwinfieldPlugin\Admin.php:31
actionadmin_menuclasses\Pronamic\WP\TwinfieldPlugin\Admin.php:33
actionadmin_enqueue_scriptsclasses\Pronamic\WP\TwinfieldPlugin\Admin.php:44
actioninitclasses\Pronamic\WP\TwinfieldPlugin\Plugin.php:45
actionplugins_loadedclasses\Pronamic\WP\TwinfieldPlugin\Plugin.php:47
actionadmin_noticesclasses\ZFramework\Util\Notice.php:27
actioninittwinfield.php:76
actionwp_twinfield_formbuilder_load_formstwinfield.php:78
actionplugins_loadedtwinfield.php:82
Maintenance & Trust

Twinfield Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedJan 2, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Twinfield Developer Profile

Pronamic

16 plugins · 5K total installs

98
trust score
Avg Security Score
97/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Twinfield

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/twinfield/assets/admin/css/bootstrap.min.css/wp-content/plugins/twinfield/assets/admin/css/bootstrap-theme.min.css/wp-content/plugins/twinfield/assets/admin/css/twinfield.css/wp-content/plugins/twinfield/assets/admin/js/bootstrap.min.js/wp-content/plugins/twinfield/assets/admin/js/twinfield.js
Script Paths
/wp-content/plugins/twinfield/assets/admin/js/bootstrap.min.js/wp-content/plugins/twinfield/assets/admin/js/twinfield.js

HTML / DOM Fingerprints

CSS Classes
twinfield-admin-pagetwinfield-customer-formtwinfield-invoice-formtwinfield-form-builder
HTML Comments
<!-- Twinfield Admin Page --><!-- Twinfield Customer Form --><!-- Twinfield Invoice Form --><!-- Twinfield Form Builder -->
Data Attributes
data-twinfield-settingdata-twinfield-field
JS Globals
twinfield_admin_params
REST Endpoints
/wp-json/twinfield/v1/customers/wp-json/twinfield/v1/invoices
Shortcode Output
[twinfield_customer_form][twinfield_invoice_form]
FAQ

Frequently Asked Questions about Twinfield