
Twitter Image Host Security & Risk Analysis
wordpress.org/plugins/twitter-image-hostHost Twitter images from your blog and keep your traffic, rather than using a service like Twitpic and losing your viewers.
Is Twitter Image Host Safe to Use in 2026?
Generally Safe
Score 85/100Twitter Image Host has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The twitter-image-host v0.6.1 plugin exhibits a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and having no recorded vulnerabilities, several concerning aspects were identified during static analysis. A significant weakness lies in its output escaping, with 0% of outputs being properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is ever displayed without sanitization. Furthermore, the use of the deprecated and dangerous `create_function` function three times introduces a significant risk, as this function can be exploited to execute arbitrary PHP code. The taint analysis, though limited in scope, found three flows with unsanitized paths, indicating a potential for input manipulation, although these were not classified as critical or high severity. The plugin has a limited attack surface with only one entry point (a shortcode), and importantly, no unprotected AJAX or REST API endpoints were found.
Key Concerns
- No proper output escaping found
- Use of dangerous function: create_function
- Unsanitized paths in taint flows
- No nonce checks implemented
- No capability checks implemented
Twitter Image Host Security Vulnerabilities
Twitter Image Host Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Twitter Image Host Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Twitter Image Host Maintenance & Trust
Maintenance Signals
Community Trust
Twitter Image Host Alternatives
MightyShare – Auto-Generated Social Media Images
mightyshare
Automatically generate social share preview images with MightyShare!
Advanced Twitter Widget
advanced-twitter-widget
Widget that will enable visitors to give you/the site a virtual beer by clicking on the widget.
TweetPress
tweetpress
Use your Wordpress blog to host the photos you post to Twitter!
Twitter2Press
twitter2press
Use your Wordpress blog to host the photos you post to Twitter!
Simple Social Images
simple-social-images
Automatically generate beautiful and branded social sharing images for posts.
Twitter Image Host Developer Profile
3 plugins · 160 total installs
How We Detect Twitter Image Host
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
twitter_image/twitter-image-host/