ETH Embed Anchor.fm Security & Risk Analysis

wordpress.org/plugins/eth-embed-anchor-fm

Allow embedding Anchor.fm podcast episodes in your content.

40 active installs v1.0 PHP 7.1+ WP 4.7+ Updated Jul 19, 2022
anchor-fmembedoembedpodcastshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ETH Embed Anchor.fm Safe to Use in 2026?

Generally Safe

Score 85/100

ETH Embed Anchor.fm has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The static analysis of eth-embed-anchor-fm v1.0 reveals a generally good security posture. The plugin demonstrates adherence to secure coding practices by not utilizing dangerous functions, employing prepared statements for all SQL queries, and properly escaping all identified output. The absence of file operations and external HTTP requests further reduces potential attack vectors. Importantly, the plugin exhibits a complete lack of identified vulnerability history, indicating a strong track record of security.

However, a significant concern arises from the complete absence of nonce checks and capability checks. While the current analysis shows zero entry points that are unprotected, this doesn't guarantee future security. The lack of these fundamental WordPress security mechanisms means that if any new entry points are introduced or if existing code paths are inadvertently exposed, they would be immediately vulnerable to various attacks, including Cross-Site Request Forgery (CSRF). The absence of taint analysis results is also noted, though this could simply mean no relevant flows were detected by the analysis tool.

In conclusion, eth-embed-anchor-fm v1.0 appears to be a well-written plugin from a secure coding perspective, with no immediate exploitable vulnerabilities identified in the static analysis or historical data. The primary weakness is the omission of essential WordPress security checks (nonces and capability checks) which, if left unaddressed, could pose a risk if the plugin's attack surface evolves. The plugin's current zero-vulnerability history is a strong positive signal.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

ETH Embed Anchor.fm Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ETH Embed Anchor.fm Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

ETH Embed Anchor.fm Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedeth-embed-anchor-fm.php:43
actionenqueue_block_editor_assetsinc\class-block-editor.php:22
actioninitinc\class-plugin.php:50
filteroembed_fetch_urlinc\class-plugin.php:52
Maintenance & Trust

ETH Embed Anchor.fm Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 19, 2022
PHP min version7.1
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

ETH Embed Anchor.fm Developer Profile

Erick Hitter

12 plugins · 48K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
2199 days
View full developer profile
Detection Fingerprints

How We Detect ETH Embed Anchor.fm

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eth-embed-anchor-fm/assets/build/index.js
Script Paths
/wp-content/plugins/eth-embed-anchor-fm/assets/build/index.js
Version Parameters
eth-embed-anchor-fm-block-editor

HTML / DOM Fingerprints

Shortcode Output
<iframe src= width= height= frameborder="0" scrolling="no"></iframe>
FAQ

Frequently Asked Questions about ETH Embed Anchor.fm