
WP-TwitterSearch Security & Risk Analysis
wordpress.org/plugins/wp-twittersearchDisplays the latest results based on a twitter search. Options include setting multiple search terms and limiting tweets shown.
Is WP-TwitterSearch Safe to Use in 2026?
Generally Safe
Score 85/100WP-TwitterSearch has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-twittersearch plugin version 1.6.2 presents a mixed security posture. On the positive side, the static analysis shows no dangerous functions, no SQL queries that are not prepared, no file operations, no external HTTP requests, and no known vulnerabilities in its history. The limited attack surface, consisting of a single shortcode, is also a positive sign. However, a significant concern is the complete lack of output escaping across all 22 identified outputs. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious code could be injected and executed in the user's browser. Additionally, the absence of nonce checks and capability checks, while not directly tied to entry points in this specific analysis, suggests a potential lack of robust authorization and CSRF protection mechanisms if the plugin were to be extended or interact with more sensitive data or actions in the future. The taint analysis yielding no flows is reassuring but doesn't negate the clear risk from unescaped output.
Key Concerns
- All outputs are unescaped
- No nonce checks
- No capability checks
WP-TwitterSearch Security Vulnerabilities
WP-TwitterSearch Code Analysis
Output Escaping
WP-TwitterSearch Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
WP-TwitterSearch Maintenance & Trust
Maintenance Signals
Community Trust
WP-TwitterSearch Alternatives
Advanced Twitter Widget
advanced-twitter-widget
Widget that will enable visitors to give you/the site a virtual beer by clicking on the widget.
Cache Tweets Widget
cache-tweets-widget
Cache Tweets Widget is a simple widget plugin with cache functionality to avoid rate limit with Twitter Search API v1.1.
Custom Twitter Feeds – A Tweets Widget or X Feed Widget
custom-twitter-feeds
Display X posts (Twitter tweets) from any public user account in a clean, attractive looking feed that updates weekly.
Search Meter
search-meter
Search Meter tracks what your readers are searching for on your site. View full details of recent searches or stats for the last day, week or month.
Easy Twitter Feed Widget Plugin
easy-twitter-feed-widget
Add twitter feeds on your WordPress site by using the Easy Twitter Feed Widget plugin.
WP-TwitterSearch Developer Profile
1 plugin · 10 total installs
How We Detect WP-TwitterSearch
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-twittersearch/wp_twittersearch_widget.css/wp-content/plugins/wp-twittersearch/wp_twittersearch.js/wp-content/plugins/wp-twittersearch/wp_twittersearch.jswp-twittersearch/wp_twittersearch_widget.css?ver=wp-twittersearch/wp_twittersearch.js?ver=HTML / DOM Fingerprints
wpts_linklovewptwittersearch_widget[wpts_widget_title]wptwittersearch_widget[wpts_widget_terms]wptwittersearch_widget[wpts_widget_nots]wptwittersearch_widget[wpts_widget_limit][wpts<span class="wpts_linklove">Powered by <a href="http://paperkilledrock.com/projects/WP-TwitterSearch">WP-TwitterSearch</a></span>