iFrame Block Security & Risk Analysis

wordpress.org/plugins/iframe-block

iFrame Block lets you insert iframes in the block editor.

800 active installs v0.1.1 PHP 5.6+ WP 5.2+ Updated Sep 1, 2025
iframe-blockinsert-iframe
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEAug 19, 2025
Safety Verdict

Is iFrame Block Safe to Use in 2026?

Mostly Safe

Score 78/100

iFrame Block is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Aug 19, 2025Updated 7mo ago
Risk Assessment

The "iframe-block" plugin version 0.1.1 presents a mixed security posture. On the positive side, the static code analysis reveals no immediately apparent vulnerabilities within the analyzed code itself. There are no dangerous functions, all SQL queries are prepared, and all outputs are properly escaped. Furthermore, the plugin exhibits a limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks.

However, a significant concern arises from the plugin's vulnerability history. The existence of one known unpatched CVE, categorized as medium severity and identified as Cross-site Scripting (XSS), overshadows the positive static analysis. This indicates that while the current code might not exhibit immediate flaws, a past vulnerability that remains unresolved poses a direct and present risk to users. The fact that the last vulnerability was in the future (2025-08-19) is likely a data anomaly or error in the provided information, but the existence of an unpatched CVE remains a critical point of attention.

In conclusion, while the "iframe-block" plugin version 0.1.1 demonstrates good practices in its code structure, the presence of an unpatched medium-severity XSS vulnerability necessitates caution. Users should be aware that even if the current code appears clean, the unresolved historical vulnerability could be exploited. The plugin's strengths lie in its minimal attack surface and internal code hygiene, but its primary weakness is the unpatched historical vulnerability.

Key Concerns

  • Unpatched CVE (Medium Severity)
Vulnerabilities
1

iFrame Block Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49411medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

iFrame Block <= 0.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 19, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

iFrame Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

iFrame Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitiframe-block.php:28
Maintenance & Trust

iFrame Block Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 1, 2025
PHP min version5.6
Downloads9K

Community Trust

Rating100/100
Number of ratings1
Active installs800
Developer Profile

iFrame Block Developer Profile

Vikas Sharma

4 plugins · 1K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect iFrame Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/iframe-block/build/index.css/wp-content/plugins/iframe-block/build/index.js
Script Paths
/wp-content/plugins/iframe-block/build/index.js
Version Parameters
iframe-block/build/index.css?ver=iframe-block/build/index.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about iFrame Block