
WP Tweet Plus Security & Risk Analysis
wordpress.org/plugins/wp-tweet-plusWP Tweet Plus allows you to add tweet button to your Wordpress site.
Is WP Tweet Plus Safe to Use in 2026?
Generally Safe
Score 85/100WP Tweet Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-tweet-plus plugin v1.2.3 demonstrates a generally good security posture with a limited attack surface and no known vulnerabilities. The use of prepared statements for all SQL queries is a significant strength, mitigating common SQL injection risks. However, the analysis reveals several areas for concern. A low percentage of output escaping (58%) suggests potential for cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is rendered without proper sanitization in the remaining outputs. The complete absence of nonce checks and capability checks across all entry points, including its single shortcode, is a notable weakness. This means that any user, regardless of their privileges, could potentially trigger actions associated with the shortcode, leading to unauthorized operations or information disclosure if the shortcode's functionality is not inherently benign. The taint analysis, while not flagging critical or high severity issues, did identify flows with unsanitized paths, which warrants further investigation to ensure no vectors for injection or information leakage exist.
Key Concerns
- Low output escaping percentage
- No nonce checks on entry points
- No capability checks on entry points
- Unsanitized paths in taint analysis
WP Tweet Plus Security Vulnerabilities
WP Tweet Plus Release Timeline
WP Tweet Plus Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Tweet Plus Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
WP Tweet Plus Maintenance & Trust
Maintenance Signals
Community Trust
WP Tweet Plus Alternatives
Customize Feeds for Twitter
twitter-tweets
Customize Feeds for Twitter plugin for WordPress. You can use this to display real time Twitter feeds on any where on your website by using shortcode …
Slim Jetpack
slimjetpack
Slim version of Jetpack unlinked from WordPress.com :) Supercharge your self-hosted wp site even you're NOT WP.COM users.
Display Tweets
display-tweets-php
Display Tweets is an easy to use, future proof Twitter feed plugin that uses PHP to make requests to the v1.1 Twitter REST API.
Peadig's Twitter Feed: Embedded Timeline WordPress Plugin
wp-twitter-feed
A simple Twitter feed that outputs your latest tweets in HTML into any post, page, template or sidebar widget. Customisable and easy to install!
Twiget Twitter Widget
twiget
A widget to display the latest Twitter status updates.
WP Tweet Plus Developer Profile
2 plugins · 710 total installs
How We Detect WP Tweet Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-tweet-plus/css/style.css/wp-content/plugins/wp-tweet-plus/js/custom.jshttps://platform.twitter.com/widgets.jswp-tweet-plus/style.css?ver=wp-tweet-plus/js/custom.js?ver=HTML / DOM Fingerprints
wptb_captionwptb_circdata-langdata-hashtagsclass="twitter-share-button"data-sizedata-countdata-via+4 morewindow.twitterWidgets<span class="wptb_caption"></span>