
Advanced iFrame Security & Risk Analysis
wordpress.org/plugins/advanced-iframeInclude content the way YOU like in an iframe that can hide and modify elements, does auto-height, forward parameters and does many, many more...
Is Advanced iFrame Safe to Use in 2026?
Mostly Safe
Score 72/100Advanced iFrame is generally safe to use. 12 past CVEs were resolved. Keep it updated.
The advanced-iframe plugin v2026.0 exhibits a mixed security posture. While it boasts a relatively small attack surface with no immediately apparent unprotected entry points in the static analysis, and a decent number of nonce and capability checks, several concerning signals emerge from the code analysis and vulnerability history. The fact that 100% of its single SQL query does not use prepared statements is a significant risk, potentially opening the door to SQL injection vulnerabilities. Furthermore, a concerning 64% of its output escaping is not properly handled, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities. The taint analysis also reveals a high severity flow with unsanitized paths, which requires immediate attention. The plugin's history of 12 known CVEs, even though none are currently marked as critical or high, and the presence of one unpatched medium vulnerability, suggests a recurring pattern of security weaknesses, primarily related to improper input validation and XSS. This history, coupled with the current code signals, indicates that while the plugin attempts some security measures, there are fundamental flaws in how it handles user-supplied data and generates output, which could be exploited.
In conclusion, while the plugin has strengths like a controlled attack surface and some security checks, the significant number of historical vulnerabilities, the lack of prepared statements for SQL queries, the substantial amount of unescaped output, and the high-severity taint flow present a considerable risk. Users should exercise caution and prioritize patching any known vulnerabilities, alongside careful review of the plugin's code for the identified issues.
Key Concerns
- Unpatched CVE
- Raw SQL without prepare
- High severity taint flow
- High percentage of unescaped output
- Bundled outdated library Freemius v1.0
Advanced iFrame Security Vulnerabilities
CVEs by Year
Severity Breakdown
12 total CVEs
Advanced iFrame <= 2025.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
Advanced iFrame <= 2025.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Advanced iFrame <= 2025.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Advanced iFrame <= 2024.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Host Header
Advanced iFrame <= 2025.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Advanced iFrame <= 2024.5 - Unauthenticated Settings Update
Advanced iFrame <= 2024.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Advanced iFrame <= 2024.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Advanced iFrame <= 2024.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Advanced iFrame <= 2023.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
Advanced iFrame <= 2023.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Advanced iFrame <= 2021.9 Reflected Cross-Site Scripting
Advanced iFrame Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced iFrame Attack Surface
AJAX Handlers 4
Shortcodes 3
WordPress Hooks 33
Scheduled Events 1
Maintenance & Trust
Advanced iFrame Maintenance & Trust
Maintenance Signals
Community Trust
Advanced iFrame Alternatives
Pym.js Embeds
pym-shortcode
A WordPress block and shortcode for embedding iframes that are responsive horizontally and vertically, using the NPR Visuals Team's Pym.js.
embedX
embedx
Show iframes easily on WordPress.
iframe
iframe
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
Insert Pages
insert-pages
Insert Pages lets you embed any WordPress content (e.g., pages, posts, custom post types) into other WordPress content using the Shortcode API.
Embed Privacy
embed-privacy
Embed Privacy prevents the loading of embedded external content and allows your site visitors to opt-in.
Advanced iFrame Developer Profile
2 plugins · 40K total installs
How We Detect Advanced iFrame
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-iframe/aip-admin.css/wp-content/plugins/advanced-iframe/aip-admin.js/wp-content/plugins/advanced-iframe/advanced-iframe.js/wp-content/plugins/advanced-iframe/advanced-iframe.css/wp-content/plugins/advanced-iframe/img/advanced-iframe.png/wp-content/plugins/advanced-iframe/aip-admin.js/wp-content/plugins/advanced-iframe/advanced-iframe.js/wp-content/plugins/advanced-iframe/aip-admin.css?ver=/wp-content/plugins/advanced-iframe/aip-admin.js?ver=/wp-content/plugins/advanced-iframe/advanced-iframe.js?ver=/wp-content/plugins/advanced-iframe/advanced-iframe.css?ver=HTML / DOM Fingerprints
advanced_iframeaip-admin-inputaip-admin-label<!-- Shortcode advanced_iframe --><!-- Shortcode advanced_iframe end --><!-- START Advanced iFrame Plugin --><!-- END Advanced iFrame Plugin -->data-advanced-iframe-wrapperdata-advanced-iframe-idadvanced_iframe_options[advanced_iframe