
Twitter Mentions As Comments Security & Risk Analysis
wordpress.org/plugins/twitter-mentions-as-commentsTwitter Mentions as Comments scours Twitter for people talking about your site & silently inserts their Tweets alongside your existing comments.
Is Twitter Mentions As Comments Safe to Use in 2026?
Generally Safe
Score 85/100Twitter Mentions As Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'twitter-mentions-as-comments' plugin v1.5.6 exhibits a mixed security posture. On the positive side, there are no reported vulnerabilities (CVEs) and the static analysis shows a limited attack surface with no exposed AJAX handlers, REST API routes, or shortcodes without authentication. The plugin also includes a reasonable number of capability checks. However, there are significant concerns within the code analysis. The presence of the `create_function` is a high-risk indicator, as it can be leveraged for remote code execution if user input is not strictly sanitized before being passed to it. Furthermore, a substantial portion of SQL queries are not using prepared statements, increasing the risk of SQL injection vulnerabilities. The low percentage of properly escaped output is also a serious concern, potentially leading to cross-site scripting (XSS) vulnerabilities.
Key Concerns
- Use of dangerous function: create_function
- SQL queries not using prepared statements
- Low percentage of properly escaped output
Twitter Mentions As Comments Security Vulnerabilities
Twitter Mentions As Comments Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Twitter Mentions As Comments Attack Surface
WordPress Hooks 27
Scheduled Events 1
Maintenance & Trust
Twitter Mentions As Comments Maintenance & Trust
Maintenance Signals
Community Trust
Twitter Mentions As Comments Alternatives
Twitter mentions in posts
twitter-mentions-in-posts
Show tweets about your posts right under them.
Open Graph and Twitter Card Tags
wonderm00ns-simple-facebook-open-graph-tags
Improve social media sharing by inserting Facebook Open Graph, Twitter Card, and SEO Meta Tags on your WordPress website pages, posts, WooCommerce pro …
Social Media Widget
social-media-widget
Adds links to all of your social media and sharing site profiles. Tons of icons come in 3 sizes, 4 icon styles, and 4 animations.
Social Media Auto Publish
social-media-auto-publish
Publish posts automatically to social media networks like Facebook, Twitter, Instagram, Tumblr, LinkedIn, Threads and Telegram.
Autopost for X (formerly Autoshare for Twitter)
autoshare-for-twitter
Automatically shares the post title or custom message and a link to the post to X/Twitter.
Twitter Mentions As Comments Developer Profile
7 plugins · 3K total installs
How We Detect Twitter Mentions As Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twitter-mentions-as-comments/includes/css/tmac.css/wp-content/plugins/twitter-mentions-as-comments/includes/css/tmac-admin.css/wp-content/plugins/twitter-mentions-as-comments/includes/js/tmac-admin.jstwitter-mentions-as-comments/includes/css/tmac.css?ver=twitter-mentions-as-comments/includes/css/tmac-admin.css?ver=twitter-mentions-as-comments/includes/js/tmac-admin.js?ver=HTML / DOM Fingerprints
tmac_settings_contentdata-tmac-post-idtmac