PowerBI Embed Reports Security & Risk Analysis

wordpress.org/plugins/embed-power-bi-reports

Embed Microsoft Power BI reports, tiles, dashboards, Q&A, etc in WordPress site with support for Row-level security (RLS).[24*7 Support]

500 active installs v1.2.3 PHP 7.0+ WP 5.5+ Updated Jan 21, 2026
embed-reportsmicrosoftoffice365power-bipowerbi
98
A · Safe
CVEs total2
Unpatched0
Last CVEOct 17, 2025
Safety Verdict

Is PowerBI Embed Reports Safe to Use in 2026?

Generally Safe

Score 98/100

PowerBI Embed Reports has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Oct 17, 2025Updated 2mo ago
Risk Assessment

The 'embed-power-bi-reports' plugin, version 1.2.3, exhibits a generally strong security posture in its current static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and 100% proper output escaping are commendable practices that significantly mitigate common web vulnerabilities. The plugin also demonstrates a reasonable awareness of security by including nonce and capability checks on its identified entry points. The limited attack surface, consisting of a single shortcode, further contributes to its perceived security.

However, the plugin's vulnerability history is a significant concern. It has a documented history of two medium-severity vulnerabilities, specifically related to Exposure of Sensitive Information and Cross-Site Scripting. While these are currently marked as patched, the presence of such issues in the past indicates potential weaknesses in input validation or sanitization that attackers could exploit if similar flaws are introduced in future updates. The external HTTP requests (seven in total) also represent a potential vector for supply chain attacks or information leakage if not handled with extreme care and validation. The bundled Select2 library, while common, could also pose a risk if it's an outdated version and has known vulnerabilities.

In conclusion, while version 1.2.3 of 'embed-power-bi-reports' appears to have implemented good secure coding practices regarding SQL and output handling, its past vulnerability record warrants careful consideration. The external HTTP requests and the potential for bundled library issues are areas that require ongoing vigilance. Users should prioritize keeping this plugin updated to the latest versions to benefit from any patched vulnerabilities and should be aware of the historical context of its security.

Key Concerns

  • Vulnerability history with 2 medium CVEs
  • 7 external HTTP requests
  • Bundled library (Select2) - potential for outdated version
Vulnerabilities
2

PowerBI Embed Reports Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-10750medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

PowerBI Embed Reports <= 1.2.0 - Unauthenticated Sensitive Information Disclosure

Oct 17, 2025 Patched in 1.2.1 (1d)
CVE-2024-11901medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

PowerBI Embed Reports <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 11, 2024 Patched in 1.1.8 (1d)
Code Analysis
Analyzed Mar 16, 2026

PowerBI Embed Reports Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
252 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
7
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

100% escaped252 total outputs
Attack Surface

PowerBI Embed Reports Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[MO_API_POWER_BI] embed-microsoft-power-bi-reports.php:77
WordPress Hooks 9
actionlogin_formembed-microsoft-power-bi-reports.php:68
actioninitembed-microsoft-power-bi-reports.php:69
actionwp_loginembed-microsoft-power-bi-reports.php:70
actionadmin_menuembed-microsoft-power-bi-reports.php:71
actionadmin_enqueue_scriptsembed-microsoft-power-bi-reports.php:72
actionadmin_enqueue_scriptsembed-microsoft-power-bi-reports.php:73
actionadmin_footerembed-microsoft-power-bi-reports.php:74
actionadmin_initembed-microsoft-power-bi-reports.php:75
actionadmin_initembed-microsoft-power-bi-reports.php:76
Maintenance & Trust

PowerBI Embed Reports Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 21, 2026
PHP min version7.0
Downloads12K

Community Trust

Rating100/100
Number of ratings23
Active installs500
Developer Profile

PowerBI Embed Reports Developer Profile

miniOrange

38 plugins · 83K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
324 days
View full developer profile
Detection Fingerprints

How We Detect PowerBI Embed Reports

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/embed-power-bi-reports/includes/css/mo_epbr_settings.min.css/wp-content/plugins/embed-power-bi-reports/includes/css/license.css/wp-content/plugins/embed-power-bi-reports/includes/css/phone.css/wp-content/plugins/embed-power-bi-reports/includes/css/datetime_style_settings.css/wp-content/plugins/embed-power-bi-reports/includes/css/mo_epbr_supportform.css/wp-content/plugins/embed-power-bi-reports/includes/js/phone.js/wp-content/plugins/embed-power-bi-reports/includes/js/timepicker.min.js/wp-content/plugins/embed-power-bi-reports/includes/js/select2.min.js+2 more
Script Paths
includes/js/mo_epbr_powerBI_display.jsincludes/js/mo_epbr_supportform.js
Version Parameters
embed-power-bi-reports/includes/css/mo_epbr_settings.min.css?ver=embed-power-bi-reports/includes/css/license.css?ver=embed-power-bi-reports/includes/css/phone.css?ver=embed-power-bi-reports/includes/css/datetime_style_settings.css?ver=embed-power-bi-reports/includes/css/mo_epbr_supportform.css?ver=embed-power-bi-reports/includes/js/phone.js?ver=embed-power-bi-reports/includes/js/timepicker.min.js?ver=embed-power-bi-reports/includes/js/select2.min.js?ver=embed-power-bi-reports/includes/js/mo_epbr_powerBI_display.js?ver=embed-power-bi-reports/includes/js/mo_epbr_supportform.js?ver=

HTML / DOM Fingerprints

CSS Classes
mo_epbr_menu_display
Data Attributes
data-reportiddata-embedurl
JS Globals
window.location.href
Shortcode Output
[MO_API_POWER_BI
FAQ

Frequently Asked Questions about PowerBI Embed Reports