
Twitter Tag Security & Risk Analysis
wordpress.org/plugins/twitter-tagLink to a users Twitter page when you include a Twitter @username in a post and tweet the user that they have been tagged.
Is Twitter Tag Safe to Use in 2026?
Generally Safe
Score 85/100Twitter Tag has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "twitter-tag" v1.0 plugin exhibits a generally positive security posture with a very small attack surface and no known vulnerabilities in its history. The complete absence of direct SQL queries, relying instead on prepared statements, and the lack of file operations or bundled libraries are strong indicators of good development practices in these areas.
However, significant concerns arise from the output escaping. With 4 total outputs and 0% properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data displayed on the frontend without proper sanitization can be exploited. Additionally, the presence of external HTTP requests without clearly defined sanitization or authorization checks for their parameters, coupled with a complete lack of nonce and capability checks for any potential entry points (even though the static analysis reports zero), indicates potential blind spots in security.
While the plugin's vulnerability history is clean, this is not a guarantee of future security, especially given the identified output escaping deficiencies. The strengths lie in its minimal attack surface and reliance on prepared statements. The primary weakness is the critical lack of output escaping, which could be exploited to inject malicious scripts. A balanced conclusion is that the plugin has a solid foundation in some areas, but critical flaws in output handling and potential unaddressed risks in external requests require immediate attention.
Key Concerns
- 0% output escaping
- External HTTP requests without auth/sanitization
- 0 nonces checks for potential entry points
- 0 capability checks for potential entry points
Twitter Tag Security Vulnerabilities
Twitter Tag Code Analysis
Output Escaping
Twitter Tag Attack Surface
WordPress Hooks 4
Maintenance & Trust
Twitter Tag Maintenance & Trust
Maintenance Signals
Community Trust
Twitter Tag Alternatives
Easy Twitter Feed Widget Plugin
easy-twitter-feed-widget
Add twitter feeds on your WordPress site by using the Easy Twitter Feed Widget plugin.
Official Twitter and Periscope plugin for WordPress. Embed content and grow your audience. Requires PHP 5.6 or greater.
Autopost for X (formerly Autoshare for Twitter)
autoshare-for-twitter
Automatically shares the post title or custom message and a link to the post to X/Twitter.
Customize Feeds for Twitter
twitter-tweets
Customize Feeds for Twitter plugin for WordPress. You can use this to display real time Twitter feeds on any where on your website by using shortcode …
Click To Tweet
click-to-tweet-by-todaymade
This plugin allows you to create beautiful Click To Tweet boxes anywhere in your blog post.
Twitter Tag Developer Profile
4 plugins · 80 total installs
How We Detect Twitter Tag
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrappmc_TT_userpmc_TT_passpmc_TT_tweet