WP Twitter Auto Publish Security & Risk Analysis

wordpress.org/plugins/twitter-auto-publish

Publish posts automatically to Twitter.

4K active installs v1.7.6 PHP 7.4+ WP 3.0+ Updated Feb 18, 2026
add-link-to-twitterpublish-post-to-twittertwittertwitter-auto-publishwp-twitter-auto-publish
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 17, 2025
Safety Verdict

Is WP Twitter Auto Publish Safe to Use in 2026?

Generally Safe

Score 99/100

WP Twitter Auto Publish has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 17, 2025Updated 1mo ago
Risk Assessment

The twitter-auto-publish plugin v1.7.6 exhibits a mixed security posture. While it has a relatively small attack surface with all identified entry points appearing to have authentication checks, there are concerning code signals. The presence of the `unserialize` function is a significant risk, as it can lead to remote code execution if user-controlled data is unserialized without proper sanitization or validation. Furthermore, a substantial portion of output (71%) is not properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities.

Taint analysis shows two flows with unsanitized paths, although they are not flagged as critical or high severity. This suggests potential weaknesses in how data is handled, even if they haven't manifested in severe vulnerabilities yet. The vulnerability history, while showing only one medium severity CVE, is also a point of concern. The last vulnerability occurred in the future (2025-11-17), which is unusual and might indicate a reporting anomaly or a future vulnerability that hasn't been disclosed yet. The common vulnerability type being XSS further reinforces the concern about unescaped output.

Overall, the plugin has some strengths in its limited attack surface and apparent authentication checks on entry points. However, the presence of dangerous functions like `unserialize`, significant unescaped output, and potential unsanitized data flows, combined with past vulnerability history, necessitates caution. Users should be aware of the potential for XSS and the risks associated with unserialization, and prompt updates when new security patches are released.

Key Concerns

  • Presence of dangerous unserialize function
  • High percentage of unescaped output
  • Taint flows with unsanitized paths
  • Medium severity CVE in history
Vulnerabilities
1

WP Twitter Auto Publish Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-12079medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Twitter Auto Publish <= 1.7.4 - Reflected Cross-Site Scripting via PostMessage

Nov 17, 2025 Patched in 1.7.5 (22d)
Code Analysis
Analyzed Mar 16, 2026

WP Twitter Auto Publish Code Analysis

Dangerous Functions
1
Raw SQL Queries
3
4 prepared
Unescaped Output
212
88 escaped
Nonce Checks
8
Capability Checks
2
File Operations
4
External Requests
7
Bundled Libraries
0

Dangerous Functions Found

unserialize$arrval=unserialize($status);admin\logs.php:77

SQL Query Safety

57% prepared7 total queries

Output Escaping

29% escaped300 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
xyz_twap_addpostmetatags (admin\metabox.php:63)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Twitter Auto Publish Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_xyz_twap_ajax_backlinkadmin\ajax-backlink.php:3
WordPress Hooks 13
actionadmin_noticesadmin\admin-notices.php:72
actionadmin_menuadmin\menu.php:3
actionadmin_enqueue_scriptsadmin\menu.php:26
actionwp_headadmin\menu.php:75
filtercron_schedulesadmin\menu.php:146
actionxyz_twap_tw_auto_reauthadmin\menu.php:153
actionadd_meta_boxesadmin\metabox.php:3
actionsave_postadmin\publish.php:3
actiontransition_post_statusadmin\publish.php:17
actioninittwitter-auto-publish.php:38
actionwp_footertwitter-auto-publish.php:65
actionadmin_inittwitter-auto-publish.php:81
filterplugin_row_metaxyz-functions.php:199

Scheduled Events 1

xyz_twap_tw_auto_reauth
Maintenance & Trust

WP Twitter Auto Publish Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version7.4
Downloads280K

Community Trust

Rating98/100
Number of ratings205
Active installs4K
Developer Profile

WP Twitter Auto Publish Developer Profile

f1logic

15 plugins · 142K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
352 days
View full developer profile
Detection Fingerprints

How We Detect WP Twitter Auto Publish

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/twitter-auto-publish/images/twap.png/wp-content/plugins/twitter-auto-publish/css/style.css/wp-content/plugins/twitter-auto-publish/js/notice.js
Script Paths
twitter-auto-publish/js/notice.js
Version Parameters
twitter-auto-publish/js/notice.js?ver=twitter-auto-publish/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
twap-settings-wrap
Data Attributes
data-twitter-auto-publish
JS Globals
xyz_script_twap_var
REST Endpoints
/wp-json/twitter-auto-publish/v1/get_logs
FAQ

Frequently Asked Questions about WP Twitter Auto Publish