
Iframe plus GET Parameters Security & Risk Analysis
wordpress.org/plugins/iframe-plus-get-parametersPasses GET parameters to iframes.
Is Iframe plus GET Parameters Safe to Use in 2026?
Generally Safe
Score 85/100Iframe plus GET Parameters has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "iframe-plus-get-parameters" plugin v1.0.2 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The code demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all identified output. Crucially, there are no critical or high severity taint flows, and the absence of dangerous function calls, file operations, and external HTTP requests further reduces the attack surface. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting consistent security development and maintenance.
Despite the positive findings, a minor concern arises from the lack of explicit nonce checks and capability checks on its single shortcode entry point. While the static analysis did not detect any unsanitized paths or unprotected entry points, the absence of these standard WordPress security mechanisms for shortcodes means that, in certain contexts or if the shortcode's functionality were to change, it could potentially be susceptible to CSRF attacks if it performs sensitive actions. However, given the limited attack surface (only one shortcode) and the lack of detected dangerous functions, the immediate risk is assessed as low. Overall, the plugin is secure in its current state, but implementing nonce and capability checks on the shortcode would further enhance its resilience against potential future threats.
Key Concerns
- Missing nonce checks
- Missing capability checks
Iframe plus GET Parameters Security Vulnerabilities
Iframe plus GET Parameters Code Analysis
Output Escaping
Iframe plus GET Parameters Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Iframe plus GET Parameters Maintenance & Trust
Maintenance Signals
Community Trust
Iframe plus GET Parameters Alternatives
URL Params
url-params
Short Code to grab any URL parameter from the Query String and display it or display conditional content.
WP Performance Score Booster – Optimize Speed, Enable Cache & Page Preload
wp-performance-score-booster
Make website faster, speed up page load time and improve performance scores in tools like Google PageSpeed Insights, GTmetrix, Pingdom, and more.
WP Theme Optimizer
wp-theme-optimizer
Optimize your WordPress theme header by removing excess tags and scripts. Make your site faster and more secure by hiding WordPress tags.
WP Version in Query String Modifier
wp-version-in-query-string-modifier
Removes or modifies the version (query string 'ver' parameter) in media resources' url.
MDI Persist Query String
mdi-persist-query-string
Persist query string parameters across page visits for tracking and analytics purposes.
Iframe plus GET Parameters Developer Profile
2 plugins · 10 total installs
How We Detect Iframe plus GET Parameters
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/iframe-plus-get-parameters/assets/js/wpp.js/wp-content/plugins/iframe-plus-get-parameters/assets/js/wpp.jsiframe-plus-get-parameters/asets/js/wpp.js?ver=1.0.0HTML / DOM Fingerprints
name='myIframe'id='myIframe'jQuery<iframe src='' name='myIframe' id='myIframe' width='' height='' frameborder='