
WP Twitter Auto Publish Security & Risk Analysis
wordpress.org/plugins/twitter-auto-publishPublish posts automatically to Twitter.
Is WP Twitter Auto Publish Safe to Use in 2026?
Generally Safe
Score 99/100WP Twitter Auto Publish has a strong security track record. Known vulnerabilities have been patched promptly.
The twitter-auto-publish plugin v1.7.6 exhibits a mixed security posture. While it has a relatively small attack surface with all identified entry points appearing to have authentication checks, there are concerning code signals. The presence of the `unserialize` function is a significant risk, as it can lead to remote code execution if user-controlled data is unserialized without proper sanitization or validation. Furthermore, a substantial portion of output (71%) is not properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities.
Taint analysis shows two flows with unsanitized paths, although they are not flagged as critical or high severity. This suggests potential weaknesses in how data is handled, even if they haven't manifested in severe vulnerabilities yet. The vulnerability history, while showing only one medium severity CVE, is also a point of concern. The last vulnerability occurred in the future (2025-11-17), which is unusual and might indicate a reporting anomaly or a future vulnerability that hasn't been disclosed yet. The common vulnerability type being XSS further reinforces the concern about unescaped output.
Overall, the plugin has some strengths in its limited attack surface and apparent authentication checks on entry points. However, the presence of dangerous functions like `unserialize`, significant unescaped output, and potential unsanitized data flows, combined with past vulnerability history, necessitates caution. Users should be aware of the potential for XSS and the risks associated with unserialization, and prompt updates when new security patches are released.
Key Concerns
- Presence of dangerous unserialize function
- High percentage of unescaped output
- Taint flows with unsanitized paths
- Medium severity CVE in history
WP Twitter Auto Publish Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Twitter Auto Publish <= 1.7.4 - Reflected Cross-Site Scripting via PostMessage
WP Twitter Auto Publish Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Twitter Auto Publish Attack Surface
AJAX Handlers 1
WordPress Hooks 13
Scheduled Events 1
Maintenance & Trust
WP Twitter Auto Publish Maintenance & Trust
Maintenance Signals
Community Trust
WP Twitter Auto Publish Alternatives
Auto Post for Twitter
auto-post-for-twitter
Publish posts automatically to Twitter.
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Custom Twitter Feeds – A Tweets Widget or X Feed Widget
custom-twitter-feeds
Display X posts (Twitter tweets) from any public user account in a clean, attractive looking feed that updates weekly.
Open Graph and Twitter Card Tags
wonderm00ns-simple-facebook-open-graph-tags
Improve social media sharing by inserting Facebook Open Graph, Twitter Card, and SEO Meta Tags on your WordPress website pages, posts, WooCommerce pro …
Social Media Widget
social-media-widget
Adds links to all of your social media and sharing site profiles. Tons of icons come in 3 sizes, 4 icon styles, and 4 animations.
WP Twitter Auto Publish Developer Profile
15 plugins · 142K total installs
How We Detect WP Twitter Auto Publish
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twitter-auto-publish/images/twap.png/wp-content/plugins/twitter-auto-publish/css/style.css/wp-content/plugins/twitter-auto-publish/js/notice.jstwitter-auto-publish/js/notice.jstwitter-auto-publish/js/notice.js?ver=twitter-auto-publish/css/style.css?ver=HTML / DOM Fingerprints
twap-settings-wrapdata-twitter-auto-publishxyz_script_twap_var/wp-json/twitter-auto-publish/v1/get_logs