
TwitterGrid Security & Risk Analysis
wordpress.org/plugins/twittergridDisplays the Twitter-Images of all your friends as a mosaic in the sidebar of your blog. The plugin is widget ready and comes with many configuration …
Is TwitterGrid Safe to Use in 2026?
Generally Safe
Score 85/100TwitterGrid has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "twittergrid" v0.3 plugin presents a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and has no known vulnerabilities (CVEs) recorded. The static analysis also indicates a lack of external HTTP requests and bundled libraries, which can reduce attack vectors. However, several concerning signals emerge from the code analysis. The presence of the deprecated `create_function` is a significant risk, as it can be exploited for remote code execution in certain contexts. Furthermore, the plugin exhibits poor output escaping practices, with only 24% of outputs properly escaped, leaving it susceptible to Cross-Site Scripting (XSS) vulnerabilities. The absence of any nonce checks or capability checks on potential entry points, even though the attack surface is reported as zero, raises questions about how these entry points are handled and if they are truly secured against unauthorized access or manipulation. While the lack of historical vulnerabilities is a strength, the current code analysis reveals specific weaknesses that require attention. The plugin's strengths lie in its database query security and absence of known CVEs, but the significant output escaping issues and the use of a dangerous function warrant caution.
Key Concerns
- Use of create_function
- Low percentage of properly escaped output
- No nonce checks detected
- No capability checks detected
TwitterGrid Security Vulnerabilities
TwitterGrid Code Analysis
Dangerous Functions Found
Output Escaping
TwitterGrid Attack Surface
WordPress Hooks 5
Maintenance & Trust
TwitterGrid Maintenance & Trust
Maintenance Signals
Community Trust
TwitterGrid Alternatives
TwitterWidget
twitterwidget
Displays your Twitter timeline in the sidebar of your blog. The plugin is widget ready and comes with many configuration options!
Customize Feeds for Twitter
twitter-tweets
Customize Feeds for Twitter plugin for WordPress. You can use this to display real time Twitter feeds on any where on your website by using shortcode …
Slim Jetpack
slimjetpack
Slim version of Jetpack unlinked from WordPress.com :) Supercharge your self-hosted wp site even you're NOT WP.COM users.
Display Tweets
display-tweets-php
Display Tweets is an easy to use, future proof Twitter feed plugin that uses PHP to make requests to the v1.1 Twitter REST API.
Peadig's Twitter Feed: Embedded Timeline WordPress Plugin
wp-twitter-feed
A simple Twitter feed that outputs your latest tweets in HTML into any post, page, template or sidebar widget. Customisable and easy to install!
TwitterGrid Developer Profile
2 plugins · 20 total installs
How We Detect TwitterGrid
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twittergrid/styles/twittergrid.csstwittergrid/style.css?ver=HTML / DOM Fingerprints
name="twittergrid[title]"name="twittergrid[username]"name="twittergrid[limit]"name="twittergrid[width]"name="twittergrid[height]"name="twittergrid[link]"+3 more