Embed social media Security & Risk Analysis

wordpress.org/plugins/embed-social-media

Simple facebook and instagram embeds without app registration. Just install and activate plugin. Open facebook and instagram oEmbed API was deprecate …

60 active installs v1.0 PHP 5.4+ WP 4.6+ Updated Oct 30, 2020
embedembed-codefacebookfbinstagram
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Embed social media Safe to Use in 2026?

Generally Safe

Score 85/100

Embed social media has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "embed-social-media" v1.0 plugin exhibits a strong security posture at first glance. The absence of identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and crucially, any apparent attack surface points to a development team that has prioritized secure coding practices. The zero recorded CVEs and the lack of any historical vulnerabilities further bolster this perception, suggesting a mature and well-maintained plugin.

However, the complete lack of any identified entry points (AJAX, REST API, shortcodes, cron events) is highly unusual for a plugin that presumably performs some function. This could indicate that the plugin's functionality is minimal or perhaps that the static analysis tooling was unable to detect them. If the plugin does indeed have functional entry points, their complete absence from the analysis raises a significant concern about the completeness of the security review. The lack of nonce and capability checks, while not directly indicating a vulnerability due to the zero attack surface, would become a critical issue if any entry points were later discovered.

In conclusion, while the plugin demonstrates excellent adherence to secure coding principles in the analyzed code and has a clean vulnerability history, the peculiar finding of zero attack surface warrants further investigation. If the plugin is indeed functional, a more thorough analysis of its entry points and their associated security checks is recommended to confirm the absence of potential vulnerabilities.

Key Concerns

  • No identified entry points
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Embed social media Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Embed social media Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Embed social media Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Embed social media Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 30, 2020
PHP min version5.4
Downloads2K

Community Trust

Rating74/100
Number of ratings3
Active installs60
Developer Profile

Embed social media Developer Profile

nechehin

3 plugins · 170 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Embed social media

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/embed-social-media/embed-social-media.php
Script Paths
//www.instagram.com/embed.jshttps://connect.facebook.net/%s/sdk.js#xfbml=1&version=v8.0

HTML / DOM Fingerprints

CSS Classes
instagram-mediafb-post
Data Attributes
data-instgrm-captioneddata-instgrm-permalinkdata-instgrm-versiondata-hrefdata-width
Shortcode Output
<blockquote class="instagram-media" data-instgrm-captioned data-instgrm-permalink="%s" data-instgrm-version="12" style="background:#FFF; border:0; border-radius:3px; max-width:540px; min-width:326px; padding:0; width:99.375%%; width:-webkit-calc(100%% - 2px); width:calc(100%% - 2px);"><div style="padding:16px;"></div></blockquote><script async defer src="//www.instagram.com/embed.js"></script><script async defer crossorigin="anonymous" src="https://connect.facebook.net/%s/sdk.js#xfbml=1&version=v8.0"></script><div class="fb-post" data-href="%s" data-width="500"></div>
FAQ

Frequently Asked Questions about Embed social media