
oEmbed as media Security & Risk Analysis
wordpress.org/plugins/oembed-as-mediaCreates an media in your library with an youtube, vimeo, hulu, and another oembed media. The plugin will fetch the data and create the media.
Is oEmbed as media Safe to Use in 2026?
Generally Safe
Score 85/100oEmbed as media has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "oembed-as-media" plugin, based on the provided static analysis, exhibits a generally strong security posture with no identified critical or high-risk vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and performing file operations safely. The presence of a nonce check, even if only one, is also a positive indicator.
However, there are areas for concern. The low percentage of properly escaped output (22%) suggests a potential for cross-site scripting (XSS) vulnerabilities. While no taint flows were identified as unsanitized, the limited scope of the taint analysis (0 flows analyzed) might mean this is an oversight in the analysis rather than a guarantee of safety. The vulnerability history is clean, which is excellent, but the static analysis findings regarding output escaping warrant attention to ensure the plugin remains secure as it evolves.
In conclusion, the plugin is off to a good start with a small attack surface and secure data handling for SQL. The primary weakness lies in output escaping, which could lead to XSS if not addressed. The lack of historical vulnerabilities is a positive sign, but this does not negate the need to rectify the identified output escaping issues.
Key Concerns
- Low percentage of properly escaped output
oEmbed as media Security Vulnerabilities
oEmbed as media Code Analysis
Output Escaping
oEmbed as media Attack Surface
WordPress Hooks 4
Maintenance & Trust
oEmbed as media Maintenance & Trust
Maintenance Signals
Community Trust
oEmbed as media Alternatives
OEmbed in Library
oembed-in-library
Easily add external files in library using OEmbed API
Remote Media Libraries
remote-medias-lite
Remote Media Libraries (RML) gives you access to third parties media libraries directly from the Wordpress Media Library.
Youtube Thumbnail as Featured Image
youtube-thumbnail-to-featured-image
Use a YouTube Thumbnail as a Featured Image for a WordPress Post. You only have to set a YouTue Video URL and the plugin does the rest.
Add Youtube Video to Media Library
add-youtube-video-to-media-library
Add Youtube Video to Media Library.
FileBird – WordPress Media Library Folders & File Manager
filebird
Organize thousands of WordPress media files in folders / categories with ease.
oEmbed as media Developer Profile
6 plugins · 70 total installs
How We Detect oEmbed as media
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oembed-as-media/HTML / DOM Fingerprints
oam_url