
oEmbed Manager Security & Risk Analysis
wordpress.org/plugins/oembed-managerManage oEmbed capabilities of your website and take a new step in the GDPR compliance of your embedded content.
Is oEmbed Manager Safe to Use in 2026?
Generally Safe
Score 100/100oEmbed Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The oEmbed Manager v3.3.0 plugin exhibits a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) and the static analysis did not reveal any critical or high severity taint flows, nor any dangerous functions or raw SQL queries without prepared statements. The majority of SQL queries are properly prepared, and a reasonable number of nonce and capability checks are present. However, there are significant areas of concern. The plugin has an unprotected AJAX handler, which represents a direct entry point for potential attacks if not properly validated. Furthermore, only 45% of output is properly escaped, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might be rendered without sufficient sanitization. The presence of file operations and external HTTP requests, while not inherently insecure, increases the attack surface and warrants careful review in conjunction with other findings.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
oEmbed Manager Security Vulnerabilities
oEmbed Manager Code Analysis
SQL Query Safety
Output Escaping
oEmbed Manager Attack Surface
AJAX Handlers 2
Shortcodes 4
WordPress Hooks 36
Maintenance & Trust
oEmbed Manager Maintenance & Trust
Maintenance Signals
Community Trust
oEmbed Manager Alternatives
Embed Consent
embed-consent
Replaces embed blocks with a confirmation to ask for consent before loading third-party resources.
Embed Privacy
embed-privacy
Embed Privacy prevents the loading of embedded external content and allows your site visitors to opt-in.
Cookie Dash
wp-gtm-data-privacy
A plugin for quickly deploying Google Tag Manager on WordPress, with a cookie consent popup that disables the container if consent is declined.
GDPR-Extensions-com – Youtube 2xClick Solution
gdpr-extensions-com-youtube-2clicksolution
Short Description: The GDPR YouTube 2xClick Solution lets you embed YouTube videos while protecting user privacy through consent-based loading.
Complianz – GDPR/CCPA Cookie Consent
complianz-gdpr
Configure your Cookie Banner, Cookie Consent and Cookie Policy with our Wizard and Cookies Scan.
oEmbed Manager Developer Profile
12 plugins · 15K total installs
How We Detect oEmbed Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oembed-manager/css/oembed-manager.css/wp-content/plugins/oembed-manager/js/oembed-manager.js/wp-content/plugins/oembed-manager/js/oembed-manager.jsoembed-manager/style.css?ver=oembed-manager/script.js?ver=HTML / DOM Fingerprints
oemm-about-logooemm-exclusion-sectiondata-oemm-idoemm_plugin_settings/wp-json/oemm/v1/settings[oemm-libraries][oemm-changelog]