
Twittrup Security & Risk Analysis
wordpress.org/plugins/twittrupUpdates Twitter when you create a new blog post utilizing an shortener service of your choice.
Is Twittrup Safe to Use in 2026?
Generally Safe
Score 85/100Twittrup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The twittrup plugin v1.1 exhibits a mixed security posture. On the positive side, there are no known CVEs, no dangerous functions are used, and all SQL queries utilize prepared statements, indicating good practices in these areas. The plugin also does not make external HTTP requests or bundle any libraries, reducing potential attack vectors. However, significant concerns arise from the static code analysis. The fact that 0% of outputs are properly escaped is a critical weakness, as it leaves the plugin highly susceptible to cross-site scripting (XSS) vulnerabilities. Furthermore, two taint analysis flows were found with unsanitized paths, indicating potential for path traversal or similar vulnerabilities, though the severity was not explicitly flagged as critical or high. The absence of nonce and capability checks on any potential entry points, despite the analysis showing zero entry points, is noted as a structural absence of common security measures that could become a concern if the attack surface were to expand in future versions or if the analysis missed certain interaction points.
Given the lack of historical vulnerabilities, it's difficult to draw definitive conclusions from past patterns. However, the current static analysis reveals critical areas for improvement, particularly concerning output escaping and the handling of unsanitized paths. While the plugin doesn't currently appear to have exploitable vulnerabilities due to its limited attack surface and lack of historical issues, the identified code-level weaknesses present a tangible risk, especially for XSS. Therefore, while not critically flawed in all aspects, the plugin requires immediate attention to its output sanitization and path handling to achieve a robust security profile.
Key Concerns
- All outputs are unescaped
- Taint flows with unsanitized paths
- No nonce checks
- No capability checks
Twittrup Security Vulnerabilities
Twittrup Code Analysis
Output Escaping
Data Flow Analysis
Twittrup Attack Surface
WordPress Hooks 2
Maintenance & Trust
Twittrup Maintenance & Trust
Maintenance Signals
Community Trust
Twittrup Alternatives
WPNeon GoCodes 2
wpneon-gocodes
Based on the original GoCodes plugin, "WPNeon GoCodes 2" is a revamnped URL redirection/shortener plugin. Great for podcasting and redirecti …
RSS Stream
rss-stream
RSS Stream displays your social feeds in a lifestream way.
Short URL Generator
shortcode-shorturl
This plugin automatically generates a Short URL for your article. You can choose your favorite provider and get multiple options.
URL Short tool by Shorterm – Simple, Fast & Private
shorterm
Lightweight WordPress URL Shortener. Create custom slugs, cloak affiliate links & track clicks without slowing down your site.
URL Shortener by Melk
url-shortener-by-melk
Create short URLs for your WordPress posts, pages, categories, tags, and custom post types automatically.
Twittrup Developer Profile
3 plugins · 30 total installs
How We Detect Twittrup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
data-twittrup-idtwittrup_settings[twittrup_display_latest_tweets]