WP-TwitterSearch Security & Risk Analysis

wordpress.org/plugins/wp-twittersearch

Displays the latest results based on a twitter search. Options include setting multiple search terms and limiting tweets shown.

10 active installs v1.6.2 PHP + WP 2.7+ Updated Oct 5, 2009
searchtwitterwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP-TwitterSearch Safe to Use in 2026?

Generally Safe

Score 85/100

WP-TwitterSearch has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The wp-twittersearch plugin version 1.6.2 presents a mixed security posture. On the positive side, the static analysis shows no dangerous functions, no SQL queries that are not prepared, no file operations, no external HTTP requests, and no known vulnerabilities in its history. The limited attack surface, consisting of a single shortcode, is also a positive sign. However, a significant concern is the complete lack of output escaping across all 22 identified outputs. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious code could be injected and executed in the user's browser. Additionally, the absence of nonce checks and capability checks, while not directly tied to entry points in this specific analysis, suggests a potential lack of robust authorization and CSRF protection mechanisms if the plugin were to be extended or interact with more sensitive data or actions in the future. The taint analysis yielding no flows is reassuring but doesn't negate the clear risk from unescaped output.

Key Concerns

  • All outputs are unescaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

WP-TwitterSearch Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP-TwitterSearch Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped22 total outputs
Attack Surface

WP-TwitterSearch Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wpts] wp-twitter-search.php:42
WordPress Hooks 4
actionadmin_initwp-twitter-search.php:37
actionadmin_menuwp-twitter-search.php:39
actionwp_dashboard_setupwp-twitter-search.php:40
actionplugins_loadedwp-twitter-search.php:41
Maintenance & Trust

WP-TwitterSearch Maintenance & Trust

Maintenance Signals

WordPress version tested2.8.4
Last updatedOct 5, 2009
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP-TwitterSearch Developer Profile

fleeting

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP-TwitterSearch

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-twittersearch/wp_twittersearch_widget.css/wp-content/plugins/wp-twittersearch/wp_twittersearch.js
Script Paths
/wp-content/plugins/wp-twittersearch/wp_twittersearch.js
Version Parameters
wp-twittersearch/wp_twittersearch_widget.css?ver=wp-twittersearch/wp_twittersearch.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpts_linklove
Data Attributes
wptwittersearch_widget[wpts_widget_title]wptwittersearch_widget[wpts_widget_terms]wptwittersearch_widget[wpts_widget_nots]wptwittersearch_widget[wpts_widget_limit]
Shortcode Output
[wpts<span class="wpts_linklove">Powered by <a href="http://paperkilledrock.com/projects/WP-TwitterSearch">WP-TwitterSearch</a></span>
FAQ

Frequently Asked Questions about WP-TwitterSearch