Twitter for WordPress Extended 2 Security & Risk Analysis

wordpress.org/plugins/twitter-extented

Twitter for WordPress Extended 2 shows your tweets, tweets for a search term (e.g. a tag), your friends timeline or the current twitter trends.

10 active installs v1.0.3.1 PHP + WP 2.1+ Updated Mar 20, 2011
twitterwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Twitter for WordPress Extended 2 Safe to Use in 2026?

Generally Safe

Score 85/100

Twitter for WordPress Extended 2 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The "twitter-extented" v1.0.3.1 plugin exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and shows no evidence of critical or high-severity issues from taint analysis, indicating good development practices regarding common vulnerability types and known exploits. Furthermore, all SQL queries are prepared, and there are no external HTTP requests or bundled libraries to worry about.

However, significant concerns arise from the static analysis. The complete absence of nonce and capability checks, coupled with a lack of proper output escaping (only 6% properly escaped), creates a substantial risk. This means that data displayed to users or processed by the plugin could be manipulated by unauthenticated or low-privileged users, potentially leading to cross-site scripting (XSS) or other injection attacks. The presence of file operations without clear context also warrants attention.

In conclusion, while the plugin benefits from a clean vulnerability history and secure database practices, the identified weaknesses in input validation and output sanitization present a clear and present danger. The lack of fundamental security checks makes it highly susceptible to common web attacks, outweighing its strengths.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks
  • Missing capability checks
  • File operations without context
Vulnerabilities
None known

Twitter for WordPress Extended 2 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Twitter for WordPress Extended 2 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

6% escaped16 total outputs
Attack Surface

Twitter for WordPress Extended 2 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionsidebar_admin_setuptwitter_extended.php:841
actionsidebar_admin_pagetwitter_extended.php:842
actionwidgets_inittwitter_extended.php:849
Maintenance & Trust

Twitter for WordPress Extended 2 Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedMar 20, 2011
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Twitter for WordPress Extended 2 Developer Profile

moroandrea

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Twitter for WordPress Extended 2

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/twitter-extented/twitter_extended.css/wp-content/plugins/twitter-extented/twitter_extended.js
Version Parameters
twitter-extented/twitter_extended.css?ver=twitter-extented/twitter_extended.js?ver=

HTML / DOM Fingerprints

CSS Classes
twittertwitter-itemtwitter-tag-message
Data Attributes
data-twitter-widget-id
JS Globals
twitter_extended_options
REST Endpoints
/wp-json/twitter/v1/get_tweets
Shortcode Output
[twitter_extended_display]
FAQ

Frequently Asked Questions about Twitter for WordPress Extended 2