
App Embed Security & Risk Analysis
wordpress.org/plugins/appizy-app-embedAppizy App Embed provides a very easy and efficient way to embed your web-calculator created with Appizy.
Is App Embed Safe to Use in 2026?
Generally Safe
Score 91/100App Embed has a strong security track record. Known vulnerabilities have been patched promptly.
The "appizy-app-embed" v2.4.0 plugin exhibits a mixed security posture. On the positive side, the static analysis indicates a lack of dangerous functions, proper use of prepared statements for SQL queries, no file operations or external HTTP requests, and no discovered taint flows. This suggests a cautious approach to handling sensitive operations. However, significant concerns arise from the incomplete output escaping, where only 33% of outputs are properly escaped, leaving a substantial portion vulnerable to injection attacks. The absence of nonce and capability checks on any entry points, including the single shortcode, is a critical oversight. This means that any user, regardless of their role or authentication status, could potentially trigger the shortcode's functionality, leading to unintended consequences or exploitation if the shortcode's logic is insecure.
The vulnerability history reveals one past medium-severity Cross-Site Scripting (XSS) vulnerability. While there are no currently unpatched CVEs, the presence of a past XSS issue, combined with the static analysis findings of poor output escaping and missing capability checks, strongly suggests a recurring weakness in input validation and output sanitization. This pattern indicates that the plugin's developers may not fully address the risks associated with user-supplied data, making it susceptible to similar vulnerabilities in the future. The plugin has a limited attack surface with only one shortcode, which is a positive aspect, but the lack of protection around this entry point negates much of this benefit.
In conclusion, while the plugin avoids certain common pitfalls like raw SQL and dangerous functions, its security is significantly undermined by insufficient output escaping and a complete lack of authentication and authorization checks on its sole entry point. The historical XSS vulnerability reinforces these concerns. Therefore, this plugin should be considered a moderate to high risk until these critical issues are addressed through thorough input validation and output encoding, along with robust capability checks for its shortcode.
Key Concerns
- Incomplete output escaping (33% proper)
- No nonce checks on entry points
- No capability checks on entry points
- Past medium XSS vulnerability
App Embed Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
App Embed <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
App Embed Code Analysis
Output Escaping
App Embed Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
App Embed Maintenance & Trust
Maintenance Signals
Community Trust
App Embed Alternatives
Calculoid – Calculator builder
calculoid-calculators-builder
Plugin makes it very easy to insert a calculator from Calculoid.com into your Wordpress website.
Import Spreadsheets from Microsoft Excel
import-spreadsheets-from-microsoft-excel
Import live, calculating spreadsheets from Microsoft Excel to WordPress. The uploaded online spreadsheet is live, and looks and feels like in Excel.
Embed Google Drive
embed-google-drive
Embed a link and preview of Google Drive Documents by pasting a shared document link into the editor.
Home Affordability Calculator
home-affordability-calculator
Use this affordability calculator to estimate a comfortable mortgage amount based on your current budget. Enter details about your income, down paymen …
Smart Calculator Builder With Google Sheets – Build Interactive Calculators with Google Sheets at Backend
smart-cost-builder-with-google-sheets
Create custom calculators for your WordPress site using your Google Sheets or Excel calculations, with dynamic, real-time results.
App Embed Developer Profile
1 plugin · 40 total installs
How We Detect App Embed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/appizy-app-embed/js/embed.js/wp-content/plugins/appizy-app-embed/css/appizy-styles.css/wp-content/plugins/appizy-app-embed/js/admin-tools-screen.js/wp-content/plugins/appizy-app-embed/js/embed.js/wp-content/plugins/appizy-app-embed/js/admin-tools-screen.jsappizy-app-embed/js/embed.js?ver=appizy-app-embed/css/appizy-styles.css?ver=appizy-app-embed/js/admin-tools-screen.js?ver=HTML / DOM Fingerprints
appizy-appappizy-app-iframeappizy-app-toolbarbutton-savebutton-printbutton-resetdata-app-idappizyApi/appizy/v1/app/[appizy id=id='app-id'enable-saveenable-print