
Embed Repo for GitHub – Display Code Repositories in Posts and Pages Security & Risk Analysis
wordpress.org/plugins/embed-githubEmbed your GitHub repositories on WordPress.
Is Embed Repo for GitHub – Display Code Repositories in Posts and Pages Safe to Use in 2026?
Generally Safe
Score 100/100Embed Repo for GitHub – Display Code Repositories in Posts and Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "embed-github" plugin v1.0.6 demonstrates a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. The code signals are also largely positive, with 100% of SQL queries using prepared statements, high output escaping rates, and a reasonable number of nonce and capability checks. Taint analysis found no critical or high severity flows, further indicating robust sanitization and validation within the analyzed code. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests consistent security attention or a lack of discovered vulnerabilities over time. However, the presence of file operations and external HTTP requests, while not inherently risky, represent potential vectors if not meticulously secured. The lack of capability checks on entry points (though there are no entry points without auth checks reported) is a minor point of attention, as is the general reliance on WordPress's core security mechanisms for protection. Overall, the plugin appears to be developed with security in mind, exhibiting good practices and a clean history. The primary areas for potential future scrutiny would be the secure implementation of its file and network operations, and ensuring that any future expansion of its entry points includes appropriate authentication and authorization checks.
Embed Repo for GitHub – Display Code Repositories in Posts and Pages Security Vulnerabilities
Embed Repo for GitHub – Display Code Repositories in Posts and Pages Release Timeline
Embed Repo for GitHub – Display Code Repositories in Posts and Pages Code Analysis
Output Escaping
Data Flow Analysis
Embed Repo for GitHub – Display Code Repositories in Posts and Pages Attack Surface
WordPress Hooks 15
Maintenance & Trust
Embed Repo for GitHub – Display Code Repositories in Posts and Pages Maintenance & Trust
Maintenance Signals
Community Trust
Embed Repo for GitHub – Display Code Repositories in Posts and Pages Alternatives
Embed Block for GitHub
embed-block-for-github
Easily embed GitHub repositories in Gutenberg Editor.
GetGit
getgit
Embeds syntax-highlighted GitHub repo content into your blog posts.
Github Embed
github-embed
Plugin that allows you to embed details from GitHub just by pasting in the URL as you would any other embed source. Currently supports:
Pastacode
pastacode
Use Pastacode to add code into your posts with the awesome PrismJs coloration library. So, past'a code!
WP Github Gist
wp-github-gist
Embed files and gist from Github in your blog posts or pages.
Embed Repo for GitHub – Display Code Repositories in Posts and Pages Developer Profile
121 plugins · 740K total installs
How We Detect Embed Repo for GitHub – Display Code Repositories in Posts and Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/embed-github/dist/style.css/wp-content/plugins/embed-github/dist/script.js/wp-content/plugins/embed-github/dist/editor.css/wp-content/plugins/embed-github/dist/script.js/wp-content/plugins/embed-github/dist/style.css?ver=/wp-content/plugins/embed-github/dist/script.js?ver=/wp-content/plugins/embed-github/dist/editor.css?ver=HTML / DOM Fingerprints
wp-block-ghb-githubdata-attributesbsdkOptInFormHandler<div class='wp-block-ghb-github