GoEmbed – Javascript Application Embedded Security & Risk Analysis

wordpress.org/plugins/go-embed

The idea to embed a Modern Javascript Application into WordPress page

10 active installs v1.0.0 PHP + WP + Updated Mar 29, 2023
buildintegratedjavascriptreactvuejs
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GoEmbed – Javascript Application Embedded Safe to Use in 2026?

Generally Safe

Score 85/100

GoEmbed – Javascript Application Embedded has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "go-embed" plugin v1.0.0 exhibits a generally positive security posture, with no known vulnerabilities or critical issues identified in the static analysis. The absence of dangerous functions, SQL queries, file operations, and external HTTP requests is a strong indicator of good security practices. The plugin also demonstrates a commendable commitment to prepared statements for any database interactions. However, a significant concern arises from the low percentage of properly escaped output. With 18% of outputs being properly escaped, there is a substantial risk of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into user-facing content. The lack of nonces and capability checks, while currently associated with a small attack surface, could become a significant risk if additional entry points are introduced or if the plugin's functionality expands. The vulnerability history is clean, suggesting diligent maintenance or a lack of focus from attackers, but this should not lead to complacency, especially given the unescaped output risk. Overall, the plugin is secure against known exploits and common severe vulnerabilities, but the high potential for XSS due to insufficient output escaping is its primary weakness.

Key Concerns

  • Low percentage of properly escaped output
  • Lack of nonce checks on entry points
  • Lack of capability checks on entry points
Vulnerabilities
None known

GoEmbed – Javascript Application Embedded Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GoEmbed – Javascript Application Embedded Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
28
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

18% escaped34 total outputs
Attack Surface

GoEmbed – Javascript Application Embedded Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[go-embed] includes\main.php:50
WordPress Hooks 5
actionadmin_menuincludes\admin-menu.php:12
actionadmin_initincludes\main.php:14
actionadmin_enqueue_scriptsincludes\main.php:15
actionplugins_loadedincludes\main.php:69
filterplugin_action_links_go-embed/go-embed.phpincludes\main.php:70
Maintenance & Trust

GoEmbed – Javascript Application Embedded Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedMar 29, 2023
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

GoEmbed – Javascript Application Embedded Developer Profile

Deliinco

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GoEmbed – Javascript Application Embedded

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/go-embed/assets/vendors/mui.min.css/wp-content/plugins/go-embed/assets/css/admin-main.css/wp-content/plugins/go-embed/assets/vendors/mui.min.js/wp-content/plugins/go-embed/apps/%s/build/jsappembed.js
Script Paths
/wp-content/plugins/go-embed/apps/%s/build/jsappembed.js
Version Parameters
go-embed/assets/vendors/mui.min.css?ver=go-embed/assets/css/admin-main.css?ver=go-embed/assets/vendors/mui.min.js?ver=

HTML / DOM Fingerprints

Data Attributes
id
Shortcode Output
<div id="Sorry but the App with idhas build error</div> <script src="
FAQ

Frequently Asked Questions about GoEmbed – Javascript Application Embedded