
Peadig's Twitter Feed: Embedded Timeline WordPress Plugin Security & Risk Analysis
wordpress.org/plugins/wp-twitter-feedA simple Twitter feed that outputs your latest tweets in HTML into any post, page, template or sidebar widget. Customisable and easy to install!
Is Peadig's Twitter Feed: Embedded Timeline WordPress Plugin Safe to Use in 2026?
Use With Caution
Score 63/100Peadig's Twitter Feed: Embedded Timeline WordPress Plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "wp-twitter-feed" v2.2 plugin exhibits a mixed security posture. On the positive side, the code analysis reveals no dangerous functions, all SQL queries use prepared statements, and there are no file operations or external HTTP requests. The limited attack surface, consisting of a single shortcode, is a good sign. However, significant concerns arise from the low percentage of properly escaped output (18%) and the complete absence of nonce checks across its entry points. The vulnerability history is a major red flag, with one high-severity Cross-Site Scripting (XSS) vulnerability from 2010 that remains unpatched. This indicates a past tendency for vulnerabilities of this type and a failure to address a known high-severity issue, suggesting a lack of proactive security maintenance.
While the current static analysis doesn't reveal critical taint flows or immediate exploitable entry points without authentication, the high percentage of unescaped output combined with the history of XSS makes the shortcode a potential vector for Cross-Site Scripting attacks if user-supplied data is not handled with extreme care. The lack of nonce checks on the shortcode, if it processes user input, further exacerbates this risk. The absence of any taint analysis results might be due to the limited complexity of the analyzed code or the absence of certain code patterns that the tool is designed to detect, rather than a true absence of risk, especially given the output escaping and nonce check deficiencies.
Key Concerns
- Unpatched High-Severity CVE
- Low output escaping percentage
- Missing nonce checks
Peadig's Twitter Feed: Embedded Timeline WordPress Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Peadig's Twitter Feed: Embedded Timeline WordPress Plugin <= 2.2 - Reflected Cross-Site Scripting
Peadig's Twitter Feed: Embedded Timeline WordPress Plugin Code Analysis
Output Escaping
Peadig's Twitter Feed: Embedded Timeline WordPress Plugin Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Peadig's Twitter Feed: Embedded Timeline WordPress Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Peadig's Twitter Feed: Embedded Timeline WordPress Plugin Alternatives
Ultimate Twitter Feeds
ultimate-twitter-feeds
Ultimate Twitter Feeds allows you to display customizable Twitter Tweets from any user timeline, any user Twitter List and single Tweet on your websi …
Import Tweets as Posts
import-tweets-as-posts
"Import Tweets as Posts" plugin allows to easily import tweets from user's timeline or search query. It has also flexibility to import …
Timeline Twitter Feed
timeline-twitter-feed
Output timeline feeds and multiple hashtags into your WordPress site as flat HTML.
Multi Account Tweet Feeds by Webline
multi-account-tweet-feeds-by-webline
A Simple plugin to show latest Tweets from a multiple Twitter accounts in the same sidebar widget,post,page or text widget content.
Find Tweets
find-tweets
Automatically converts blog post snippets into less than 140 character tweets. Adds in shortlinks to drive traffic to your website.
Peadig's Twitter Feed: Embedded Timeline WordPress Plugin Developer Profile
11 plugins · 4K total installs
How We Detect Peadig's Twitter Feed: Embedded Timeline WordPress Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-twitter-feed/css/style.csswp-twitter-feed/css/style.css?ver=HTML / DOM Fingerprints
twitter-feedTwitter Feed for WordPress: http://peadig.com/wordpress-plugins/wp-twitter-feed/data-widget-iddata-sizedata-langdata-show-counttwitterWidgets_ga<div class="twitter-feed"><a class="twitter-timeline"<p><a href="https://twitter.com/<p>Powered by <a href="http://peadig.com/wordpress-plugins/wp-twitter-feed/">Twitter Feed</a></p>