
Twitter Hash Tag Shortcode Security & Risk Analysis
wordpress.org/plugins/twitter-hash-tag-shortcodeDisplaying the most recent twitter status updates for a particular hash tag in your posts/pages using shortcode.
Is Twitter Hash Tag Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100Twitter Hash Tag Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "twitter-hash-tag-shortcode" v0.6.2 plugin exhibits a generally good security posture, with no known vulnerabilities in its history and a limited attack surface. The static analysis shows a complete absence of dangerous functions, SQL queries are exclusively handled by prepared statements, and there are no file operations or external HTTP requests flagged as malicious by taint analysis. The plugin also avoids bundling external libraries, which can be a source of outdated and vulnerable code. However, there are areas for improvement. A significant concern is the low rate of proper output escaping, with only 46% of outputs being safely handled. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. Furthermore, the complete lack of nonce checks and capability checks on the identified entry point (a shortcode) is a notable weakness. While there are no AJAX handlers or REST API routes without checks, the shortcode itself represents an unprotected entry point that could potentially be exploited, especially if it interacts with user-controlled data. In conclusion, while the plugin's foundation is solid due to its avoidance of critical issues like raw SQL and dangerous functions, the insufficient output escaping and absence of authorization checks on its sole entry point present a tangible risk that should be addressed.
Key Concerns
- Low output escaping percentage
- No nonce checks on entry points
- No capability checks on entry points
Twitter Hash Tag Shortcode Security Vulnerabilities
Twitter Hash Tag Shortcode Release Timeline
Twitter Hash Tag Shortcode Code Analysis
Output Escaping
Twitter Hash Tag Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Twitter Hash Tag Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Twitter Hash Tag Shortcode Alternatives
No alternatives data available yet.
Twitter Hash Tag Shortcode Developer Profile
19 plugins · 9K total installs
How We Detect Twitter Hash Tag Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twitter-hash-tag-shortcode/inc/SimplePanelClass.phpHTML / DOM Fingerprints
twitter-hash-tagview-all{$token->errors['message']}{$raw_response->errors['http_request_failed'][0]}<div class='twitter-hash-tag'><div class='view-all'><a href='http://search.twitter.com/search?q=%23</div>