
CodePen Embed Block Security & Risk Analysis
wordpress.org/plugins/codepen-embed-blockAn (official) block for CodePen Embeds.
Is CodePen Embed Block Safe to Use in 2026?
Mostly Safe
Score 78/100CodePen Embed Block is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "codepen-embed-block" plugin exhibits a generally good security posture based on the static analysis, with no detected dangerous functions, raw SQL queries, unescaped output, or file operations. The complete absence of identified attack vectors like AJAX handlers, REST API routes, and shortcodes is a significant positive. Furthermore, the presence of capability checks is a good practice. However, the plugin has a known medium severity vulnerability for Cross-site Scripting (XSS) that remains unpatched, which is a significant concern. The single recorded CVE, even if medium, suggests a potential for input validation issues that could be exploited. While the static analysis shows no immediate threats, the history of an unpatched XSS vulnerability indicates a past weakness that needs careful monitoring and resolution. The plugin's strengths lie in its clean code and lack of immediate exploitable entry points, but the outstanding CVE presents a clear and present risk.
Key Concerns
- Unpatched Medium Severity CVE
CodePen Embed Block Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CodePen Embed Block <= 1.1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
CodePen Embed Block Code Analysis
Output Escaping
CodePen Embed Block Attack Surface
WordPress Hooks 3
Maintenance & Trust
CodePen Embed Block Maintenance & Trust
Maintenance Signals
Community Trust
CodePen Embed Block Alternatives
CodePen oEmbed
codepen-oembed
Add CodePen to the available oEmbed providers
AppsFruit Elementor Embed
appsfruit-embed-for-elementor
Embed Elementor pages, templates, and sections anywhere using shortcodes or Gutenberg blocks with conditional display options.
Advanced iFrame
advanced-iframe
Include content the way YOU like in an iframe that can hide and modify elements, does auto-height, forward parameters and does many, many more...
Insert Pages
insert-pages
Insert Pages lets you embed any WordPress content (e.g., pages, posts, custom post types) into other WordPress content using the Shortcode API.
Advance Custom HTML – Show Live Code, Share Snippets, Embed Code, and Style Them Your Way.
advance-custom-html
Advance Custom HTML lets you write and display HTML, CSS, PHP, and other code snippets on WordPress with live preview and syntax highlighting.
CodePen Embed Block Developer Profile
2 plugins · 2K total installs
How We Detect CodePen Embed Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/codepen-embed-block/build/view.asset.php/wp-content/plugins/codepen-embed-block/build/index.js/wp-content/plugins/codepen-embed-block/build/index.css/wp-content/plugins/codepen-embed-block/build/index.jscodepen-embed-block/build/index.css?ver=codepen-embed-block/build/index.js?ver=HTML / DOM Fingerprints
wp-block-codepen-embed-block-codepen-embed-blockdata-codepen-hrefcodepenEmbedBlock