oEmbed as media Security & Risk Analysis

wordpress.org/plugins/oembed-as-media

Creates an media in your library with an youtube, vimeo, hulu, and another oembed media. The plugin will fetch the data and create the media.

10 active installs v$version$ PHP + WP 3.8.1+ Updated Dec 30, 2014
librarymediaoembedyoutube
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is oEmbed as media Safe to Use in 2026?

Generally Safe

Score 85/100

oEmbed as media has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "oembed-as-media" plugin, based on the provided static analysis, exhibits a generally strong security posture with no identified critical or high-risk vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and performing file operations safely. The presence of a nonce check, even if only one, is also a positive indicator.

However, there are areas for concern. The low percentage of properly escaped output (22%) suggests a potential for cross-site scripting (XSS) vulnerabilities. While no taint flows were identified as unsanitized, the limited scope of the taint analysis (0 flows analyzed) might mean this is an oversight in the analysis rather than a guarantee of safety. The vulnerability history is clean, which is excellent, but the static analysis findings regarding output escaping warrant attention to ensure the plugin remains secure as it evolves.

In conclusion, the plugin is off to a good start with a small attack surface and secure data handling for SQL. The primary weakness lies in output escaping, which could lead to XSS if not addressed. The lack of historical vulnerabilities is a positive sign, but this does not negate the need to rectify the identified output escaping issues.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

oEmbed as media Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

oEmbed as media Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

22% escaped9 total outputs
Attack Surface

oEmbed as media Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filtermedia_upload_tabsadmin\media-upload.php:13
actionmedia_upload_oembedasmediaadmin\media-upload.php:60
actionadmin_initadmin\media-upload.php:121
actionedit_form_after_titleadmin\media-upload.php:136
Maintenance & Trust

oEmbed as media Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedDec 30, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

oEmbed as media Developer Profile

dgmike

6 plugins · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect oEmbed as media

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
/wp-content/plugins/oembed-as-media/

HTML / DOM Fingerprints

Data Attributes
oam_url
FAQ

Frequently Asked Questions about oEmbed as media