
Include Me Security & Risk Analysis
wordpress.org/plugins/include-meInclude Me helps to include any external file (textual, HTML or PHP) in posts or pages.
Is Include Me Safe to Use in 2026?
Generally Safe
Score 97/100Include Me has a strong security track record. Known vulnerabilities have been patched promptly.
The 'include-me' plugin v1.3.7 exhibits a mixed security posture. While the static analysis reveals good practices such as 100% output escaping and the presence of nonce and capability checks, the lack of prepared statements for its single SQL query is a significant concern, especially given its vulnerability history. The total absence of unprotected entry points (AJAX, REST API) is a strong positive sign, indicating that immediate public-facing code execution is well-protected. However, the plugin's past vulnerabilities, including Cross-site Scripting and PHP Remote File Inclusion, are critical red flags. The presence of these severe vulnerability types in its history, despite no currently unpatched CVEs, suggests a recurring pattern of insecure coding practices that may not be fully addressed by the current version. While the static analysis does not reveal active critical or high severity taint flows, the historical data strongly indicates a latent risk that users should be aware of. Therefore, users should proceed with caution and ensure diligent updating practices.
Key Concerns
- SQL queries not using prepared statements
- Total known CVEs (2) in history
- High severity historical CVE (1)
- Medium severity historical CVE (1)
Include Me Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Include Me <= 1.3.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Include Me <= 1.2.1 - Local File Inclusion leading to Authenticated Remote Code Execution
Include Me Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Include Me Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Include Me Maintenance & Trust
Maintenance Signals
Community Trust
Include Me Alternatives
HG3-Include
hg3-include
Plugin to include any code (html, php, javascript,...) directly into the WordPress editor.
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager
insert-headers-and-footers
Easily add code snippets in WordPress. Insert header & footer scripts, add PHP code snippets with conditional logic, insert ads pixel code, and more.
WPS Hide Login
wps-hide-login
Change wp-login.php to anything you want.
Code Snippets
code-snippets
An easy, clean and simple way to enhance your site with code snippets.
Header Footer Code Manager
header-footer-code-manager
Easily add tracking code snippets, conversion pixels, or other scripts required by third party services for analytics, marketing, or chat features.
Include Me Developer Profile
14 plugins · 515K total installs
How We Detect Include Me
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<p>Include me shortcode: the file attribute is empty</p><p>The provided file (<code></code>) does not exist. <strong>This message is shown only to administrators</strong>.</p><p>The provided file (<code>