Widgets for Tiktok Feed Security & Risk Analysis

wordpress.org/plugins/widgets-for-tiktok-video-feed

Tiktok Feed Widgets. Display your Tiktok feed on your website to increase engagement, sales and SEO.

70 active installs v1.7.9 PHP 7.0+ WP 6.2+ Updated Feb 26, 2026
feedgallerytiktokvideowidget
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 25, 2025
Safety Verdict

Is Widgets for Tiktok Feed Safe to Use in 2026?

Generally Safe

Score 99/100

Widgets for Tiktok Feed has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 25, 2025Updated 1mo ago
Risk Assessment

The static analysis of "widgets-for-tiktok-video-feed" v1.7.9 indicates a generally good security posture. The plugin demonstrates strong adherence to secure coding practices, with all SQL queries using prepared statements and all output being properly escaped. The absence of dangerous functions, file operations, and a large attack surface with unprotected entry points is also commendable. Nonce and capability checks are present, further bolstering its defenses.

Key Concerns

  • Flows with unsanitized paths detected
  • External HTTP requests detected
  • Medium severity vulnerability in history
Vulnerabilities
1

Widgets for Tiktok Feed Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-8906medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Widgets for Tiktok Feed <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 25, 2025 Patched in 1.7.4 (1d)
Code Analysis
Analyzed Mar 16, 2026

Widgets for Tiktok Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
458 escaped
Nonce Checks
15
Capability Checks
4
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

100% escaped460 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
<admin> (include\admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Widgets for Tiktok Feed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
filterrocket_minify_excluded_external_jsinclude\cache-plugin-filters.php:13
filterrocket_exclude_jsinclude\cache-plugin-filters.php:14
filterrocket_delay_js_exclusionsinclude\cache-plugin-filters.php:15
filterlitespeed_optimize_js_excludesinclude\cache-plugin-filters.php:16
filtersgo_javascript_combine_excluded_external_pathsinclude\cache-plugin-filters.php:17
filtersgo_css_combine_excludeinclude\cache-plugin-filters.php:18
filterrocket_rucss_safelistinclude\cache-plugin-filters.php:58
filterscript_loader_taginclude\cache-plugin-filters.php:63
filterstyle_loader_taginclude\cache-plugin-filters.php:78
actionwp_footertrustindex-feed-plugin.class.php:4810
actionadmin_footertrustindex-feed-plugin.class.php:4811
filterfilesystem_methodtrustindex-feed-plugin.class.php:4895
actionadmin_noticestrustindex-feed-plugin.class.php:4920
actionplugins_loadedwidgets-for-tiktok-video-feed.php:34
actionadmin_menuwidgets-for-tiktok-video-feed.php:35
filterplugin_action_linkswidgets-for-tiktok-video-feed.php:36
filterplugin_row_metawidgets-for-tiktok-video-feed.php:37
actioninitwidgets-for-tiktok-video-feed.php:38
actionadmin_enqueue_scriptswidgets-for-tiktok-video-feed.php:39
actioninitwidgets-for-tiktok-video-feed.php:41
actioninitwidgets-for-tiktok-video-feed.php:57
filterscript_loader_tagwidgets-for-tiktok-video-feed.php:58
actionrest_api_initwidgets-for-tiktok-video-feed.php:64
actionadmin_noticeswidgets-for-tiktok-video-feed.php:105
actionelementor/widgets/widgets_registeredwidgets-for-tiktok-video-feed.php:147
actionelementor/elements/categories_registeredwidgets-for-tiktok-video-feed.php:151
actionwp_enqueue_scriptswidgets-for-tiktok-video-feed.php:160
Maintenance & Trust

Widgets for Tiktok Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

Widgets for Tiktok Feed Developer Profile

Trustindex

32 plugins · 976K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
87 days
View full developer profile
Detection Fingerprints

How We Detect Widgets for Tiktok Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/widgets-for-tiktok-video-feed/assets/css/frontend-notifictions.css/wp-content/plugins/widgets-for-tiktok-video-feed/assets/js/frontend-notifictions.js
Version Parameters
widgets-for-tiktok-video-feed/style.css?ver=widgets-for-tiktok-video-feed/assets/css/frontend-notifictions.css?ver=widgets-for-tiktok-video-feed/assets/js/frontend-notifictions.js?ver=

HTML / DOM Fingerprints

CSS Classes
trustindex-notification-rowtrustindex-star-rowti-close-notificationti-button-primaryti-remind-laterti-hide-notificationtrustindex-noticetrustindex-notice-dismiss
Data Attributes
data-close-urldata-redirect-url
REST Endpoints
/wp-json/widgets-for-tiktok-video-feed/v1/get-token/wp-json/widgets-for-tiktok-video-feed/v1/troubleshooting/wp-json/widgets-for-tiktok-video-feed/v1/refresh-data
FAQ

Frequently Asked Questions about Widgets for Tiktok Feed