
Embed Block for GitHub Security & Risk Analysis
wordpress.org/plugins/embed-block-for-githubEasily embed GitHub repositories in Gutenberg Editor.
Is Embed Block for GitHub Safe to Use in 2026?
Generally Safe
Score 100/100Embed Block for GitHub has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "embed-block-for-github" plugin v0.3 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified CVEs in its history, coupled with a clean taint analysis report, suggests a history of secure development and maintenance. The code signals also reveal positive practices like 100% usage of prepared statements for SQL queries. However, there are some areas of concern that warrant attention. The plugin has an external HTTP request, which, while not inherently insecure, can be a vector for certain types of attacks if not handled with proper sanitization and validation, especially if the target URL is user-controlled or dynamic. Furthermore, the output escaping is only 58% properly escaped, indicating a significant portion of outputs might be vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is involved in those outputs. The lack of capability checks and nonce checks, while not leading to direct vulnerabilities in the analyzed attack surface, represents a missed opportunity for robust security, especially if the plugin's functionality were to expand or integrate with user-modifiable data in the future.
Key Concerns
- Output escaping is not fully implemented
- External HTTP requests exist
- No capability checks
- No nonce checks
Embed Block for GitHub Security Vulnerabilities
Embed Block for GitHub Code Analysis
Output Escaping
Embed Block for GitHub Attack Surface
WordPress Hooks 1
Maintenance & Trust
Embed Block for GitHub Maintenance & Trust
Maintenance Signals
Community Trust
Embed Block for GitHub Alternatives
Embed Repo for GitHub – Display Code Repositories in Posts and Pages
embed-github
Embed your GitHub repositories on WordPress.
PDF Embedder
pdf-embedder
Seamlessly embed PDFs into your content, with customizations and intelligent responsive resizing, and no third-party services or iframes.
Spotlight Social Feeds – Block, Shortcode, and Widget
spotlight-social-photo-feeds
Instagram feeds made easy. Responsive, customizable, accessible, and SEO-friendly out of the box. Includes Instagram blocks & oEmbed support.
Embed PDF Viewer
embed-pdf-viewer
Embed a PDF from the Media Library or elsewhere via oEmbed or as a block into an iframe tag.
Advance Custom HTML – Show Live Code, Share Snippets, Embed Code, and Style Them Your Way.
advance-custom-html
Advance Custom HTML lets you write and display HTML, CSS, PHP, and other code snippets on WordPress with live preview and syntax highlighting.
Embed Block for GitHub Developer Profile
24 plugins · 64K total installs
How We Detect Embed Block for GitHub
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/embed-block-for-github/repository-block.js/wp-content/plugins/embed-block-for-github/repository-block-editor.css/wp-content/plugins/embed-block-for-github/repository-block.css/wp-content/plugins/embed-block-for-github/repository-block.jsembed-block-for-github/repository-block.js?ver=embed-block-for-github/repository-block-editor.css?ver=embed-block-for-github/repository-block.css?ver=HTML / DOM Fingerprints
ebg-br-wrapper-dark-mode-onebg-br-wrapper-dark-mode-offdata-github_urldata-darck_modewp.blocks.registerBlockTypewp.componentswp.elementwp.i18nwp.editor/wp-json/embed-block-for-github/repository%%_WRAPPER_DARK_MODE_%%%%_DATA_AVATAR_URL_%%%%_DATA_REPO_URL_%%%%_DATA_REPO_NAME_%%