Twitter Digest Security & Risk Analysis

wordpress.org/plugins/twitter-digest

Creates a daily or weekly post containing tweets from a twitter account.

100 active installs v2.9 PHP + WP 2.7+ Updated Unknown
post-digesttweettwitter
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Twitter Digest Safe to Use in 2026?

Generally Safe

Score 100/100

Twitter Digest has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "twitter-digest" v2.9 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and performing capability checks. The lack of known CVEs and a recorded vulnerability history also suggests a relatively stable past. However, several concerning signals emerge from the static analysis. The presence of the `create_function` dangerous function, even if only used twice, introduces a potential for code injection if not handled with extreme care or if its usage is not fully understood. Furthermore, the complete lack of output escaping on all identified outputs is a significant concern, potentially leading to cross-site scripting (XSS) vulnerabilities if any dynamic data is displayed to users without proper sanitization.

Key Concerns

  • Dangerous function 'create_function' found
  • 0% of outputs properly escaped
  • 0 Nonce checks found
Vulnerabilities
None known

Twitter Digest Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Twitter Digest Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

create_functioncreate_function(twitter-digest.php:349
create_functioncreate_function(twitter-digest.php:357

Output Escaping

0% escaped1 total outputs
Attack Surface

Twitter Digest Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionws_td_digest_eventtwitter-digest.php:44
actionadmin_menutwitter-digest.php:445

Scheduled Events 1

ws_td_digest_event
Maintenance & Trust

Twitter Digest Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedUnknown
PHP min version
Downloads14K

Community Trust

Rating90/100
Number of ratings4
Active installs100
Developer Profile

Twitter Digest Developer Profile

tbeck

2 plugins · 110 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Twitter Digest

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/twitter-digest/css/twitter-digest-main.css/wp-content/plugins/twitter-digest/css/twitter-digest-style.css/wp-content/plugins/twitter-digest/js/twitter-digest.js
Script Paths
/wp-content/plugins/twitter-digest/js/twitter-digest.js
Version Parameters
twitter-digest/css/twitter-digest-main.css?ver=twitter-digest/css/twitter-digest-style.css?ver=twitter-digest/js/twitter-digest.js?ver=

HTML / DOM Fingerprints

CSS Classes
ws_tweet_list
FAQ

Frequently Asked Questions about Twitter Digest