Embed React Build Security & Risk Analysis

wordpress.org/plugins/embed-react-build

It is a plugin that allows you to integrate your ReactJS builds into wordpress.

20 active installs v1.0.3 PHP 7.0+ WP 4.7+ Updated Unknown
buildembedreact
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Embed React Build Safe to Use in 2026?

Generally Safe

Score 100/100

Embed React Build has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "embed-react-build" v1.0.3 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, the consistent use of prepared statements for SQL queries, and the 100% proper output escaping all indicate good development practices. Furthermore, the plugin has no recorded vulnerabilities, which is a very positive sign for its security over time.

However, there are a few areas that warrant attention. The presence of an external HTTP request without explicit details on its purpose or validation is a potential concern. While the attack surface is small and the single shortcode does not appear to have authentication or capability checks directly mentioned, the static analysis indicates 0 unprotected entry points, which is reassuring. The lack of nonce checks is also a notable omission, especially if the shortcode or any internal operations interact with user-supplied data in a sensitive manner.

Overall, the plugin appears to be securely coded with no known historical vulnerabilities. The primary areas for improvement would be to scrutinize the external HTTP request and ensure that all entry points, even those not explicitly flagged as unprotected, are adequately secured against potential misuse, particularly if any user-supplied data can influence the external request or internal logic. The current score reflects a solid foundation with minor areas for refinement.

Key Concerns

  • External HTTP request present
  • No nonce checks implemented
Vulnerabilities
None known

Embed React Build Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Embed React Build Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0
Attack Surface

Embed React Build Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[embed_react_build] embed-react-build.php:26
Maintenance & Trust

Embed React Build Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedUnknown
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Embed React Build Developer Profile

nsei

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Embed React Build

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/embed-react-build/assets/css/wp-content/plugins/embed-react-build/assets/js
Script Paths
/wp-content/plugins/embed-react-build/assets/js/runtime-main.js/wp-content/plugins/embed-react-build/assets/js/main.js/wp-content/plugins/embed-react-build/assets/js/2.chunk.js/wp-content/plugins/embed-react-build/assets/js/0.chunk.js/wp-content/plugins/embed-react-build/assets/js/1.chunk.js
Version Parameters
embed-react-build/assets/js/runtime-main.js?ver=embed-react-build/assets/js/main.js?ver=embed-react-build/assets/js/2.chunk.js?ver=embed-react-build/assets/js/0.chunk.js?ver=embed-react-build/assets/js/1.chunk.js?ver=embed-react-build/assets/css/main.css?ver=

HTML / DOM Fingerprints

JS Globals
manifest
Shortcode Output
<div id="root"></div>
FAQ

Frequently Asked Questions about Embed React Build