
PowerBI Embed Reports Security & Risk Analysis
wordpress.org/plugins/embed-power-bi-reportsEmbed Microsoft Power BI reports, tiles, dashboards, Q&A, etc in WordPress site with support for Row-level security (RLS).[24*7 Support]
Is PowerBI Embed Reports Safe to Use in 2026?
Generally Safe
Score 98/100PowerBI Embed Reports has a strong security track record. Known vulnerabilities have been patched promptly.
The 'embed-power-bi-reports' plugin, version 1.2.3, exhibits a generally strong security posture in its current static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and 100% proper output escaping are commendable practices that significantly mitigate common web vulnerabilities. The plugin also demonstrates a reasonable awareness of security by including nonce and capability checks on its identified entry points. The limited attack surface, consisting of a single shortcode, further contributes to its perceived security.
However, the plugin's vulnerability history is a significant concern. It has a documented history of two medium-severity vulnerabilities, specifically related to Exposure of Sensitive Information and Cross-Site Scripting. While these are currently marked as patched, the presence of such issues in the past indicates potential weaknesses in input validation or sanitization that attackers could exploit if similar flaws are introduced in future updates. The external HTTP requests (seven in total) also represent a potential vector for supply chain attacks or information leakage if not handled with extreme care and validation. The bundled Select2 library, while common, could also pose a risk if it's an outdated version and has known vulnerabilities.
In conclusion, while version 1.2.3 of 'embed-power-bi-reports' appears to have implemented good secure coding practices regarding SQL and output handling, its past vulnerability record warrants careful consideration. The external HTTP requests and the potential for bundled library issues are areas that require ongoing vigilance. Users should prioritize keeping this plugin updated to the latest versions to benefit from any patched vulnerabilities and should be aware of the historical context of its security.
Key Concerns
- Vulnerability history with 2 medium CVEs
- 7 external HTTP requests
- Bundled library (Select2) - potential for outdated version
PowerBI Embed Reports Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
PowerBI Embed Reports <= 1.2.0 - Unauthenticated Sensitive Information Disclosure
PowerBI Embed Reports <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
PowerBI Embed Reports Code Analysis
Bundled Libraries
Output Escaping
PowerBI Embed Reports Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
PowerBI Embed Reports Maintenance & Trust
Maintenance Signals
Community Trust
PowerBI Embed Reports Alternatives
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
wpo365-login
WordPress + Microsoft Entra | Ext. ID | B2C | M365 Integration for your Digital Workplace. For SSO, Mail, Roles, Access, Profiles, SharePoint, PowerBI …
Microsoft Clarity
microsoft-clarity
How do you make your website great? Clarity can help you quickly see what's working on your site and where people get stuck. And it's free.
eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams
eroom-zoom-meetings-webinar
eRoom is the best WordPress Zoom Meeting and Webinar Plugin. eRoom Zoom WordPress plugin enables integration with Zoom, Google Meet, Microsoft Teams.
WPO365 | MICROSOFT 365 GRAPH MAILER
wpo365-msgraphmailer
Send WordPress emails from a M365 / Exchange Online Mailbox using Microsoft Graph, leveraging OAuth for authentication which is more secure than SMTP
Microsoft Advertising Universal Event Tracking (UET)
microsoft-advertising-universal-event-tracking-uet
The official plugin for setting up Microsoft Advertising UET
PowerBI Embed Reports Developer Profile
38 plugins · 83K total installs
How We Detect PowerBI Embed Reports
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/embed-power-bi-reports/includes/css/mo_epbr_settings.min.css/wp-content/plugins/embed-power-bi-reports/includes/css/license.css/wp-content/plugins/embed-power-bi-reports/includes/css/phone.css/wp-content/plugins/embed-power-bi-reports/includes/css/datetime_style_settings.css/wp-content/plugins/embed-power-bi-reports/includes/css/mo_epbr_supportform.css/wp-content/plugins/embed-power-bi-reports/includes/js/phone.js/wp-content/plugins/embed-power-bi-reports/includes/js/timepicker.min.js/wp-content/plugins/embed-power-bi-reports/includes/js/select2.min.js+2 moreincludes/js/mo_epbr_powerBI_display.jsincludes/js/mo_epbr_supportform.jsembed-power-bi-reports/includes/css/mo_epbr_settings.min.css?ver=embed-power-bi-reports/includes/css/license.css?ver=embed-power-bi-reports/includes/css/phone.css?ver=embed-power-bi-reports/includes/css/datetime_style_settings.css?ver=embed-power-bi-reports/includes/css/mo_epbr_supportform.css?ver=embed-power-bi-reports/includes/js/phone.js?ver=embed-power-bi-reports/includes/js/timepicker.min.js?ver=embed-power-bi-reports/includes/js/select2.min.js?ver=embed-power-bi-reports/includes/js/mo_epbr_powerBI_display.js?ver=embed-power-bi-reports/includes/js/mo_epbr_supportform.js?ver=HTML / DOM Fingerprints
mo_epbr_menu_displaydata-reportiddata-embedurlwindow.location.href[MO_API_POWER_BI