
Github Embed Security & Risk Analysis
wordpress.org/plugins/github-embedPlugin that allows you to embed details from GitHub just by pasting in the URL as you would any other embed source. Currently supports:
Is Github Embed Safe to Use in 2026?
Generally Safe
Score 100/100Github Embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "github-embed" v2.2.1 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin has a minimal attack surface, with no observable AJAX handlers, REST API routes, or shortcodes exposed without authentication. Furthermore, all detected SQL queries utilize prepared statements, and file operations are absent, reducing common vectors for exploitation. The output escaping is also reasonably good, with 84% of outputs properly escaped, although there's a slight concern that 16% are not, which could be a minor risk in specific scenarios. The complete lack of known CVEs and a clean vulnerability history indicate a history of responsible development and maintenance. However, the absence of nonce checks and capability checks across its entry points, coupled with a single external HTTP request without clear sanitization context, presents a potential area for concern that warrants further investigation if the plugin has any dynamic functionality beyond basic embedding.
Key Concerns
- 16% of outputs are not properly escaped
- No nonce checks on entry points
- No capability checks on entry points
Github Embed Security Vulnerabilities
Github Embed Code Analysis
SQL Query Safety
Output Escaping
Github Embed Attack Surface
WordPress Hooks 7
Scheduled Events 1
Maintenance & Trust
Github Embed Maintenance & Trust
Maintenance Signals
Community Trust
Github Embed Alternatives
Embed PDF Viewer
embed-pdf-viewer
Embed a PDF from the Media Library or elsewhere via oEmbed or as a block into an iframe tag.
Disable Embeds
disable-embeds
Don’t like the enhanced embeds in WordPress 4.4? Easily disable the feature using this plugin.
Embed Privacy
embed-privacy
Embed Privacy prevents the loading of embedded external content and allows your site visitors to opt-in.
oEmbed Plus
oembed-plus
Adds support for embedding Facebook and Instagram posts in Block Editor (Gutenberg) and Classic Editor.
Embedly
embedly
The Embedly Plugin extends WordPress's auto-embed feature to give your blog more media types and style options.
Github Embed Developer Profile
4 plugins · 41K total installs
How We Detect Github Embed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/github-embed/css/github-embed.cssgithub-embed/css/github-embed.css?ver=HTML / DOM Fingerprints
github-logo-octocatdata-github-embedgithub_embed[github_embed