
TwitchPress Login Extension Security & Risk Analysis
wordpress.org/plugins/twitchpress-login-extensionDoes not support Twitch API 6: Helix yet! Add Twitch social login and registration to your TwitchPress service. This plugin acts as an extension to T …
Is TwitchPress Login Extension Safe to Use in 2026?
Generally Safe
Score 85/100TwitchPress Login Extension has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The twitchpress-login-extension plugin v1.9.0 exhibits a strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength. Furthermore, the code signals indicate good development practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and a high percentage of output escaping. The lack of file operations, external HTTP requests, and the absence of taint analysis findings further reinforce this positive assessment.
The plugin's vulnerability history is also exceptionally clean, with no known CVEs recorded. This lack of past vulnerabilities, combined with the current static analysis results, suggests a well-maintained and secure codebase. However, it's important to note the complete absence of nonce checks and capability checks. While the current attack surface appears minimal and potentially does not require these, their absence could become a concern if new features are added that introduce more sensitive entry points without implementing these crucial security measures. Overall, the plugin is assessed as highly secure at present, with the primary area for potential future concern being the implementation of authentication and authorization checks if the attack surface expands.
Key Concerns
- Missing nonce checks
- Missing capability checks
TwitchPress Login Extension Security Vulnerabilities
TwitchPress Login Extension Code Analysis
Output Escaping
TwitchPress Login Extension Attack Surface
WordPress Hooks 33
Maintenance & Trust
TwitchPress Login Extension Maintenance & Trust
Maintenance Signals
Community Trust
TwitchPress Login Extension Alternatives
TwitchPress Embed Everything
twitchpress-embed-everything
Add the Embed Everything plugin to your blog after installing the core TwitchPress plugin called Channel Solution for Twitch.
Twitch Player
ttv-easy-embed-player
Twitch streams for your WordPress website - Twitch Player unlocks a compact, cinema-style layout, great for embedded stream experience.
Twitch Status
twitch-status
Inserts Twitch.tv stream player and chatbox in your posts, stream widget and online status tags in your menus. Supports multiple channels.
Online Indicator For Twitch
online-indicator-for-twitch
Add a customisable streaming indicator to your WordPress site to let your visitors know when your Twitch channel is live.
Twitch Rail
ttv-easy-embed
Twitch streams for your WordPress website - Twitch Rail unlocks a horizontal scrolling layout, to display many streams in a small space.
TwitchPress Login Extension Developer Profile
3 plugins · 30 total installs
How We Detect TwitchPress Login Extension
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twitchpress-login-extension/css/twitchpress-login-styles.css/wp-content/plugins/twitchpress-login-extension/js/twitchpress-login-scripts.js/wp-content/plugins/twitchpress-login-extension/js/twitchpress-login-scripts.jstwitchpress-login-extension/css/twitchpress-login-styles.css?ver=twitchpress-login-extension/js/twitchpress-login-scripts.js?ver=HTML / DOM Fingerprints
twitchpress-login-button<!-- TwitchPress Login Button -->data-twitchpress-login-noncedata-twitchpress-login-ajax-urldata-twitchpress-login-redirecttwitchpress_login_params[twitchpress_connect_button]