
Disable Embeds Security & Risk Analysis
wordpress.org/plugins/disable-embedsDon’t like the enhanced embeds in WordPress 4.4? Easily disable the feature using this plugin.
Is Disable Embeds Safe to Use in 2026?
Generally Safe
Score 100/100Disable Embeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "disable-embeds" v1.5.0 plugin exhibits a very strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate robust security practices, with no dangerous functions, all SQL queries using prepared statements, and all outputs being properly escaped. The plugin also avoids file operations and external HTTP requests. The lack of any recorded vulnerabilities, including critical or high severity issues, and the absence of common vulnerability types in its history, further reinforce this positive assessment.
Despite the excellent static analysis and vulnerability history, the total absence of nonce checks and capability checks in the code is a minor concern. While the plugin currently has no exposed entry points that would necessitate these checks, future updates or changes could inadvertently introduce vulnerabilities if these checks are not implemented as a general security practice. Overall, "disable-embeds" v1.5.0 appears to be a highly secure plugin, with its strengths far outweighing any potential weaknesses suggested by the analysis.
Key Concerns
- No nonce checks present
- No capability checks present
Disable Embeds Security Vulnerabilities
Disable Embeds Code Analysis
Disable Embeds Attack Surface
WordPress Hooks 9
Maintenance & Trust
Disable Embeds Maintenance & Trust
Maintenance Signals
Community Trust
Disable Embeds Alternatives
Haiku Deck for WordPress
haiku-deck-oembed
Register Haiku Deck as an oEmbed content provider
GeniiPress Disable Embeds
geniipress-disable-embeds
Disables the oEmbed feature from core, for a performance gain.
Embed Optimizer
embed-optimizer
Optimizes the performance of embeds through lazy-loading, adding dns-prefetch links, and reserving space to reduce layout shifts.
Embed PDF Viewer
embed-pdf-viewer
Embed a PDF from the Media Library or elsewhere via oEmbed or as a block into an iframe tag.
Embed Privacy
embed-privacy
Embed Privacy prevents the loading of embedded external content and allows your site visitors to opt-in.
Disable Embeds Developer Profile
4 plugins · 53K total installs
How We Detect Disable Embeds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/disable-embeds/build/index.js/wp-content/plugins/disable-embeds/build/index.jsHTML / DOM Fingerprints
/oembed/1.0/embed