Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more Security & Risk Analysis

wordpress.org/plugins/embed-extended

Embed any external content into WordPress posts and pages. It works seamlessly on Gutenberg, Elementor, classic editor, the embed shortcode, as well a …

400 active installs v1.4.0 PHP 5.6+ WP 4.6+ Updated Oct 23, 2023
embed-mapsembed-videooembedopen-graphsource-code
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEApr 1, 2025
Download
Safety Verdict

Is Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more Safe to Use in 2026?

Use With Caution

Score 64/100

Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Apr 1, 2025Updated 2yr ago
Risk Assessment

The "embed-extended" v1.4.0 plugin presents a mixed security posture. While it avoids dangerous functions, uses prepared statements for SQL, and doesn't engage in risky file operations or external HTTP requests, significant concerns arise from its attack surface and vulnerability history. The static analysis reveals three AJAX handlers that lack any authentication or capability checks, directly exposing them to potential abuse. Furthermore, all analyzed taint flows exhibited unsanitized paths, although thankfully none reached critical or high severity. The plugin's history of a medium-severity Cross-Site Request Forgery (CSRF) vulnerability, which is currently unpatched, is a particularly worrying sign. This indicates a recurring pattern of security weaknesses that could be exploited by attackers. While the absence of certain common vulnerabilities is positive, the open AJAX endpoints and the unaddressed past vulnerability create a tangible risk, suggesting a need for urgent review and patching.

Key Concerns

  • 3 unprotected AJAX handlers
  • Unpatched CVE
  • 4 taint flows with unsanitized paths
  • 57% of outputs properly escaped
  • No nonce checks on AJAX handlers
  • No capability checks on AJAX handlers
Vulnerabilities
1 published

Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31784medium · 4.3Cross-Site Request Forgery (CSRF)

Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more <= 1.4.0 - Cross-Site Request Forgery

Apr 1, 2025Unpatched
Version History

Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more Release Timeline

v1.4.0Current1 CVE
v1.3.01 CVE
v1.2.31 CVE
v1.2.21 CVE
v1.2.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
36
47 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

57% escaped83 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
save (includes\class-embed-extended-admin-settings.php:94)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_embed_extended_iframeembed-extended.php:60
noprivwp_ajax_embed_extended_iframeembed-extended.php:61
authwp_ajax_embed_extended_notice_dismissincludes\class-embed-extended-admin.php:18
WordPress Hooks 15
actionplugins_loadedembed-extended.php:51
actionenqueue_block_editor_assetsembed-extended.php:53
filterpre_oembed_resultembed-extended.php:55
filterrest_endpointsembed-extended.php:56
filteroembed_providersembed-extended.php:58
actionadmin_menuincludes\class-embed-extended-admin.php:15
actionadmin_noticesincludes\class-embed-extended-admin.php:16
actionadmin_enqueue_scriptsincludes\class-embed-extended-admin.php:17
filterembed_extended_admin_settings_tabsincludes\class-embed-extended-debug.php:34
filteroembed_providersincludes\class-embed-extended-debug.php:42
filterload_default_embedsincludes\class-embed-extended-debug.php:43
filterembed_oembed_discoverincludes\class-embed-extended-debug.php:48
filteroembed_ttlincludes\class-embed-extended-debug.php:53
filterrest_oembed_ttlincludes\class-embed-extended-debug.php:54
filterembed_extended_cache_patternsincludes\class-embed-extended-fetcher.php:103
Maintenance & Trust

Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedOct 23, 2023
PHP min version5.6
Downloads11K

Community Trust

Rating98/100
Number of ratings7
Active installs400
Developer Profile

Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more Developer Profile

Rudy Susanto

1 plugin · 400 total installs

69
trust score
Avg Security Score
64/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/embed-extended/assets/css/embed-extended.css/wp-content/plugins/embed-extended/assets/js/embed-extended.js
Script Paths
/wp-content/plugins/embed-extended/assets/js/embed-extended.js
Version Parameters
embed-extended/assets/css/embed-extended.css?ver=embed-extended/assets/js/embed-extended.js?ver=

HTML / DOM Fingerprints

JS Globals
window.embed_extended_admin
REST Endpoints
/wp-json/embed-extended/
FAQ

Frequently Asked Questions about Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more