
QuadLayers TikTok Feed Security & Risk Analysis
wordpress.org/plugins/wp-tiktok-feedDisplay beautiful and responsive galleries on your website from your TikTok feed account.
Is QuadLayers TikTok Feed Safe to Use in 2026?
Mostly Safe
Score 78/100QuadLayers TikTok Feed is generally safe to use. 1 past CVE were resolved. Keep it updated.
The wp-tiktok-feed plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a lack of identified dangerous functions, no exploitable file operations, and a very low percentage of unescaped output. The absence of external HTTP requests and the presence of nonce and capability checks are also encouraging signs of good development practices.
However, significant concerns arise from the vulnerability history and the SQL query handling. The presence of one unpatched medium severity CVE, specifically related to Missing Authorization, is a critical red flag. This, combined with the fact that 100% of its SQL queries are not using prepared statements, strongly suggests a potential for SQL injection vulnerabilities. While the attack surface appears minimal in terms of entry points, the lack of proper SQL sanitization on existing queries and the past authorization issue indicate areas of weakness.
In conclusion, while the plugin demonstrates some strengths in output escaping and avoiding common dangerous functions, the unpatched vulnerability and the insecure handling of SQL queries present a substantial risk. The past authorization issue, in particular, highlights a recurring problem that needs immediate attention. Users should exercise caution until the unpatched CVE is addressed and the SQL query practices are improved.
Key Concerns
- Unpatched CVE (medium severity)
- 100% of SQL queries un-prepared
QuadLayers TikTok Feed Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
QuadLayers TikTok Feed <= 4.6.4 - Missing Authorization
QuadLayers TikTok Feed Code Analysis
SQL Query Safety
Output Escaping
QuadLayers TikTok Feed Attack Surface
WordPress Hooks 24
Maintenance & Trust
QuadLayers TikTok Feed Maintenance & Trust
Maintenance Signals
Community Trust
QuadLayers TikTok Feed Alternatives
Feed for TikTok
feed-for-tiktok
Displays the feed of any user on TikTok plus account information. Available for Elementor and shortcode.
Feeds for TikTok (TikTok feed, video, and gallery plugin)
feeds-for-tiktok
The best way to display TikTok videos on your WordPress website. Display clean, customizable, and responsive TikTok feeds from your TikTok account.
Custom Feed for TikTok – Social Post Feed Plugin for TikTok
custom-feed-for-tiktok
Explore the power of Custom Feed for TikTok, the top-notch plugin for displaying your videos with user-friendly and up-to-date features
Easy TikTok Feed – TikTok Video, Feed & Gallery Plugin
easy-tiktok-feed
Embed TikTok feeds in WordPress — responsive, SEO-ready, and monetization-friendly. No coding or tokens needed.
Gallery Feed for TikTok – Show TikTok Videos in Grid, Masonry, or Slideshow
ws-tiktok-feed
Embed TikTok videos and feeds in WordPress. Show likes, views, comments, shares & user info with Grid, Blog, Masonry, or Slideshow layouts.
QuadLayers TikTok Feed Developer Profile
17 plugins · 654K total installs
How We Detect QuadLayers TikTok Feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-tiktok-feed/assets/css/frontend.css/wp-content/plugins/wp-tiktok-feed/assets/css/frontend.min.css/wp-content/plugins/wp-tiktok-feed/assets/js/frontend.js/wp-content/plugins/wp-tiktok-feed/assets/js/frontend.min.jshttps://apps.elfsight.com/p/platform.jswp-tiktok-feed/assets/css/frontend.css?ver=wp-tiktok-feed/assets/js/frontend.js?ver=HTML / DOM Fingerprints
qlttf-frontend-wrapper<!-- wp-tiktok-feed -->data-qlttf-iddata-qlttf-feed-idqlttf_frontend_params/wp-json/qlttf/v1/feed[tiktok_feed