
iframe Wrapper Security & Risk Analysis
wordpress.org/plugins/iframe-wrapperA small little plugin to embed an auto resizing iframe into a WordPress page or post.
Is iframe Wrapper Safe to Use in 2026?
Generally Safe
Score 85/100iframe Wrapper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "iframe-wrapper" plugin version 0.1.1 exhibits a generally strong security posture based on the provided static analysis. The code appears to follow good practices by not utilizing dangerous functions, employing prepared statements for all SQL queries, and ensuring all output is properly escaped. Furthermore, the absence of file operations, external HTTP requests, and any recorded vulnerability history suggests a well-developed and secure plugin. The limited attack surface, consisting of a single shortcode and no unprotected entry points, further reinforces this positive assessment.
Despite the strong code-level security, there are no explicit nonce or capability checks identified in the static analysis. While the limited attack surface and absence of known vulnerabilities reduce the immediate risk, the lack of these fundamental WordPress security mechanisms represents a potential weakness. If the shortcode were to process user-supplied data in the future, or if the plugin's functionality evolved to include more sensitive operations, the absence of proper authorization and validation could become a concern. The current version, however, appears safe due to its minimal functionality and clean code.
Key Concerns
- Missing nonce checks
- Missing capability checks
iframe Wrapper Security Vulnerabilities
iframe Wrapper Code Analysis
iframe Wrapper Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
iframe Wrapper Maintenance & Trust
Maintenance Signals
Community Trust
iframe Wrapper Alternatives
WP Wrapper
wp-wrapper
Wrapper for WordPress pages using iFrame. Various options in admin panel
HostFact bestelformulier integratie
hostfact-bestelformulier-integratie
Eenvoudige manier om het bestelformulier van HostFact in de Wordpress website te integreren.
iframe
iframe
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
Advanced iFrame
advanced-iframe
Include content the way YOU like in an iframe that can hide and modify elements, does auto-height, forward parameters and does many, many more...
Embed Privacy
embed-privacy
Embed Privacy prevents the loading of embedded external content and allows your site visitors to opt-in.
iframe Wrapper Developer Profile
4 plugins · 550 total installs
How We Detect iframe Wrapper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/iframe-wrapper/iframe-wrapper.js/wp-content/plugins/iframe-wrapper/iframe-wrapper.jsiframe-wrapper.js?ver=HTML / DOM Fingerprints
iframe-wrapper<!-- url value not passed --><iframe scrolling="no" class="iframe-wrapper" style="width:100%;border:0;overflow-y:hidden;" src="