LS oEmbed support for Scratch Mit Security & Risk Analysis

wordpress.org/plugins/ls-oembed-support-for-scratch-mit

Adds oEmbed support for https://scratch.mit.edu projects in WordPress posts, pages and custom post types.

100 active installs v2.1 PHP + WP 4.0+ Updated Dec 23, 2024
educationoembedscratch-mitscratch-project
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is LS oEmbed support for Scratch Mit Safe to Use in 2026?

Generally Safe

Score 92/100

LS oEmbed support for Scratch Mit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "ls-oembed-support-for-scratch-mit" plugin v2.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, or external HTTP requests is commendable. Furthermore, the plugin's entry points are well-protected, with no unprotected AJAX handlers, REST API routes, shortcodes, or cron events. The lack of any vulnerability history, including CVEs, suggests a history of secure development or diligent maintenance by its authors.

While the code analysis reveals no immediate threats, the complete absence of identified flows in the taint analysis is unusual for a plugin of any complexity. This could indicate that the plugin is very simple and has limited data handling, or it could mean the analysis tool was unable to trace potential data flows within the plugin's code. The lack of nonces and capability checks, while not a direct vulnerability in this case due to the absence of exposed entry points, could become a concern if the plugin were to be extended or modified in the future without implementing these fundamental security measures.

Overall, the plugin appears secure as presented. The strengths lie in its minimal attack surface and apparent adherence to secure coding practices for the identified components. The main area for consideration, though not a current vulnerability, is the potential for future risks if the plugin's functionality expands without the explicit addition of robust access controls and input validation mechanisms.

Vulnerabilities
None known

LS oEmbed support for Scratch Mit Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

LS oEmbed support for Scratch Mit Release Timeline

v2.1Current
v2.0
v1.0
Code Analysis
Analyzed Mar 16, 2026

LS oEmbed support for Scratch Mit Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

LS oEmbed support for Scratch Mit Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionplugins_loadedscratchmit.php:19
Maintenance & Trust

LS oEmbed support for Scratch Mit Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 23, 2024
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

LS oEmbed support for Scratch Mit Developer Profile

lenasterg

10 plugins · 2K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
3763 days
View full developer profile
Detection Fingerprints

How We Detect LS oEmbed support for Scratch Mit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<div align="center"> <iframe allowtransparency="true" width="" height="" src="//scratch.mit.edu/projects/embed//?autostart=false" scrolling="no" frameborder="0" allowtransparency="true" allowfullscreen="" mozallowfullscreen="" webkitallowfullscreen=""></iframe>
FAQ

Frequently Asked Questions about LS oEmbed support for Scratch Mit