
Twitter Goodies Widgets Security & Risk Analysis
wordpress.org/plugins/twitter-goodies-widgetsUses the twitter goodies widgets API to create offical twitter widgets (profiles, lists, faves and search) straight from your control panel.
Is Twitter Goodies Widgets Safe to Use in 2026?
Generally Safe
Score 85/100Twitter Goodies Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "twitter-goodies-widgets" v1.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query sanitation, utilizing prepared statements exclusively, and shows no history of known vulnerabilities. The attack surface, while present with AJAX handlers and shortcodes, appears limited and all entry points are reported as protected, with the presence of nonce and capability checks further bolstering this. However, critical concerns arise from the analysis of dangerous functions and output escaping. The use of `create_function` is a significant security risk, as it can be exploited to inject and execute arbitrary PHP code. Furthermore, the complete lack of proper output escaping across all identified outputs leaves the plugin highly susceptible to Cross-Site Scripting (XSS) attacks. While the taint analysis found no unsanitized paths, the combination of `create_function` and unescaped output creates a substantial risk of code injection and persistent XSS.
Key Concerns
- Use of dangerous function (create_function)
- Output not properly escaped
Twitter Goodies Widgets Security Vulnerabilities
Twitter Goodies Widgets Release Timeline
Twitter Goodies Widgets Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Twitter Goodies Widgets Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Twitter Goodies Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Twitter Goodies Widgets Alternatives
Easy Twitter Feed Widget Plugin
easy-twitter-feed-widget
Add twitter feeds on your WordPress site by using the Easy Twitter Feed Widget plugin.
Official Twitter and Periscope plugin for WordPress. Embed content and grow your audience. Requires PHP 5.6 or greater.
Customize Feeds for Twitter
twitter-tweets
Customize Feeds for Twitter plugin for WordPress. You can use this to display real time Twitter feeds on any where on your website by using shortcode …
Twiget Twitter Widget
twiget
A widget to display the latest Twitter status updates.
Ultimate Twitter Feeds
ultimate-twitter-feeds
Display lightweight Twitter feeds. Fetch profiles, lists, or single tweets with customizable sizes and language support.
Twitter Goodies Widgets Developer Profile
13 plugins · 176K total installs
How We Detect Twitter Goodies Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twitter-goodies-widgets/colorpicker/farbtastic.js/wp-content/plugins/twitter-goodies-widgets/colorpicker/farbtastic.cssHTML / DOM Fingerprints
TWTR<script type="text/javascript">new TWTR.Widget().render().start();