
Embed Post Security & Risk Analysis
wordpress.org/plugins/embed-postEmbed a Post within another Post or Page using [embed_post] shortcode.
Is Embed Post Safe to Use in 2026?
Generally Safe
Score 85/100Embed Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "embed-post" plugin v1.1 demonstrates a generally strong security posture based on the provided static analysis. The code exhibits excellent practices by utilizing prepared statements for all SQL queries and ensuring proper output escaping, with no identified dangerous functions or file operations. The attack surface is minimal, consisting solely of one shortcode, and crucially, there are no unprotected entry points. The absence of external HTTP requests and the lack of bundled libraries further reduce potential vulnerabilities.
However, a significant concern arises from the complete absence of nonce checks and capability checks. While the current analysis shows no direct vulnerabilities, the lack of these fundamental security measures means that the shortcode, even if it doesn't directly execute sensitive operations now, could become a vector for CSRF attacks or privilege escalation if any future modifications introduce such risks or if the shortcode's functionality is extended. The vulnerability history is clean, indicating a low likelihood of existing known issues, but the lack of protective checks remains a latent risk.
In conclusion, the plugin is well-coded with good basic security hygiene. The primary weakness lies in the omission of authorization and anti-CSRF mechanisms, which, while not currently exploited, represents a significant oversight in robust WordPress security. Addressing these checks would elevate the plugin's security to a more resilient level against potential future threats.
Key Concerns
- Missing nonce checks
- Missing capability checks
Embed Post Security Vulnerabilities
Embed Post Code Analysis
Embed Post Attack Surface
Shortcodes 1
Maintenance & Trust
Embed Post Maintenance & Trust
Maintenance Signals
Community Trust
Embed Post Alternatives
Lumeer Embed
lumeer-embed
Embed a Lumeer project within any Post or Page using [lumeer_embed] shortcode.
Extended Page List
extended-page-lists
Add custom configured page lists to your posts, pages and sidebar.
End Content
end-content
Allows you to add content to the end of pages, posts or both.
Advanced Excerpt
advanced-excerpt
Control the appearance of WordPress post excerpts
Toggle wpautop
toggle-wpautop
Easily disable the default wpautop filter on a post by post basis.
Embed Post Developer Profile
1 plugin · 100 total installs
How We Detect Embed Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
embed_postembed_post_more<div class="embed_post"><a href="" title="Read More" class="embed_post_more">Read More...</a><a href="