
Custom iFrame – Embed PDFs, Videos, and External Content in WordPress (Elementor & Gutenberg) Security & Risk Analysis
wordpress.org/plugins/custom-iframeEasily embed secure, SEO-friendly, and responsive iFrames in WordPress using Elementor or Gutenberg with lazy loading, auto-height adjustment, and dyn …
Is Custom iFrame – Embed PDFs, Videos, and External Content in WordPress (Elementor & Gutenberg) Safe to Use in 2026?
Generally Safe
Score 99/100Custom iFrame – Embed PDFs, Videos, and External Content in WordPress (Elementor & Gutenberg) has a strong security track record. Known vulnerabilities have been patched promptly.
The custom-iframe plugin v2.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any critical or high severity taint flows, raw SQL queries, or file operations is commendable. Furthermore, the plugin correctly implements nonce checks on all identified AJAX handlers, demonstrating a good understanding of WordPress security best practices for handling user input. The high percentage of properly escaped outputs is also a positive indicator, reducing the risk of cross-site scripting vulnerabilities within the plugin's output generation.
However, a concern arises from the historical vulnerability data. The plugin has a record of one known CVE, specifically related to Cross-site Scripting (XSS). Although currently unpatched CVEs are zero, the presence of past XSS vulnerabilities, even if a medium severity, suggests that input sanitization might not always be robust, or that developers need to remain vigilant in preventing such issues. The fact that the last vulnerability was dated in the future (2025-09-22) is likely an anomaly in the data entry and should be disregarded in the current assessment. While the current version shows no immediate critical flaws, the historical pattern warrants continued monitoring and thorough testing of any future updates.
Key Concerns
- Past medium severity XSS vulnerability
Custom iFrame – Embed PDFs, Videos, and External Content in WordPress (Elementor & Gutenberg) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Custom iFrame for Elementor <= 1.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
Custom iFrame – Embed PDFs, Videos, and External Content in WordPress (Elementor & Gutenberg) Code Analysis
Output Escaping
Custom iFrame – Embed PDFs, Videos, and External Content in WordPress (Elementor & Gutenberg) Attack Surface
AJAX Handlers 7
WordPress Hooks 17
Maintenance & Trust
Custom iFrame – Embed PDFs, Videos, and External Content in WordPress (Elementor & Gutenberg) Maintenance & Trust
Maintenance Signals
Community Trust
Custom iFrame – Embed PDFs, Videos, and External Content in WordPress (Elementor & Gutenberg) Alternatives
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud!
templately
Templately is an AI-powered WordPress templates cloud for Elementor and Gutenberg that offers 6,500+ ready template designs for a wide range of niches
Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor)
content-views-query-and-display-post-page
Easy to show posts, pages, custom posts in customizable grid, list, slider, accordion... Available as Widgets (for Elementor), Shortcode, and Blocks.
EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
embedpress
EmbedPress lets you embed videos, pages, social feeds, embed PDF 3D flipbooks & other content on WordPress without coding & enhance storytelling.
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
woolentor-addons
ShopLentor – More than a WooCommerce builder. A complete growth plugin to boost conversions, UX, and sales for your store.
Custom iFrame – Embed PDFs, Videos, and External Content in WordPress (Elementor & Gutenberg) Developer Profile
2 plugins · 3K total installs
How We Detect Custom iFrame – Embed PDFs, Videos, and External Content in WordPress (Elementor & Gutenberg)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-iframe/assets/css/style.css/wp-content/plugins/custom-iframe/assets/js/widget.js/wp-content/plugins/custom-iframe/assets/js/dismiss-notice.js/wp-content/plugins/custom-iframe/assets/css/admin/admin.css/wp-content/plugins/custom-iframe/assets/css/admin/deactivate-feedback.css/wp-content/plugins/custom-iframe/assets/js/admin/deactivate-feedback.js/wp-content/plugins/custom-iframe/assets/js/widget.js/wp-content/plugins/custom-iframe/assets/js/dismiss-notice.js/wp-content/plugins/custom-iframe/assets/js/admin/deactivate-feedback.jscustom-iframe/assets/css/style.css?ver=custom-iframe/assets/js/widget.js?ver=custom-iframe/assets/js/dismiss-notice.js?ver=custom-iframe/assets/css/admin/admin.css?ver=custom-iframe/assets/css/admin/deactivate-feedback.css?ver=custom-iframe/assets/js/admin/deactivate-feedback.js?ver=HTML / DOM Fingerprints
customIframeNoticecustifFeedback