
Xhanch – My Twitter Security & Risk Analysis
wordpress.org/plugins/xhanch-my-twitterThe best plugin to display your latest tweets, replies, direct messages, retweets, auto and manual tweet and lots more. Support multiple accounts
Is Xhanch – My Twitter Safe to Use in 2026?
Mostly Safe
Score 84/100Xhanch – My Twitter is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "xhanch-my-twitter" plugin v2.7.9 exhibits a mixed security posture. While it demonstrates good practices in SQL query handling, utilizing prepared statements exclusively, and includes some nonce and capability checks, several concerning areas require attention. The presence of dangerous functions like `unserialize` and `create_function` is a significant red flag, especially when combined with taint analysis revealing two flows with unsanitized paths, classified as high severity. These could potentially lead to remote code execution or other serious vulnerabilities if exploited.
The plugin's vulnerability history shows one previously disclosed high-severity vulnerability, historically of the Cross-Site Request Forgery (CSRF) type. Although currently unpatched CVEs are zero, the past occurrence of a high-severity issue, coupled with the static analysis findings, suggests a pattern of potential weaknesses. The limited attack surface (one shortcode) and lack of unprotected entry points are positive aspects, but the identified code signals and taint issues outweigh these strengths.
In conclusion, while the plugin shows some security awareness, the presence of dangerous functions, high-severity unsanitized taint flows, and a history of high-severity vulnerabilities necessitate caution. Further investigation and code review are recommended to mitigate these risks, particularly around the usage of `unserialize` and `create_function` and the identified unsanitized paths.
Key Concerns
- High severity taint flows with unsanitized paths
- Use of dangerous function: unserialize
- Use of dangerous function: create_function
- 16% of outputs properly escaped (low escaping)
- Previous High severity CVE
Xhanch – My Twitter Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Xhanch – My Twitter <= 2.7.6 - Cross-Site Request Forgery
Xhanch – My Twitter Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Xhanch – My Twitter Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Xhanch – My Twitter Maintenance & Trust
Maintenance Signals
Community Trust
Xhanch – My Twitter Alternatives
Tools for Twitter
twitter-tools
Tools for Twitter is a plugin that creates a complete integration between your WordPress blog and your Twitter account.
Twiget Twitter Widget
twiget
A widget to display the latest Twitter status updates.
Import Tweets as Posts
import-tweets-as-posts
"Import Tweets as Posts" plugin allows to easily import tweets from user's timeline or search query. It has also flexibility to import …
Twitter Digest
twitter-digest
Creates a daily or weekly post containing tweets from a twitter account.
Easy Retweet
easy-retweet
Adds a Tweet button to your WordPress posts
Xhanch – My Twitter Developer Profile
3 plugins · 220 total installs
How We Detect Xhanch – My Twitter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xhanch-my-twitter/css/css.phpHTML / DOM Fingerprints
xmttweet_avatartweet_list<![CDATA[]]>Starting to generate outputFinisheddata-iddata-tweet-iddata-accountdata-tweet-urlwindow.xmt_base_url[xmt