
oEmbed Plus Security & Risk Analysis
wordpress.org/plugins/oembed-plusAdds support for embedding Facebook and Instagram posts in Block Editor (Gutenberg) and Classic Editor.
Is oEmbed Plus Safe to Use in 2026?
Generally Safe
Score 85/100oEmbed Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the oembed-plus plugin version 1.6 exhibits an excellent security posture. The code analysis reveals a remarkably clean codebase with no identified dangerous functions, no direct SQL queries (all are prepared), and all identified output is properly escaped. Furthermore, there are no file operations or external HTTP requests, and crucially, no identifiable attack surface through AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or capability checks. The taint analysis also shows zero flows with unsanitized paths, indicating a strong defense against common injection vulnerabilities.
The plugin's vulnerability history further reinforces its security. With zero recorded CVEs of any severity, and no common vulnerability types or recent past issues, it suggests a consistently secure development and maintenance process. This lack of historical vulnerabilities, combined with the current clean static analysis, points to a plugin that has likely been built with security as a priority and has undergone thorough vetting.
In conclusion, oembed-plus v1.6 appears to be a highly secure plugin. Its strengths lie in its minimal attack surface, robust code practices like prepared statements and proper output escaping, and a spotless vulnerability history. There are no apparent weaknesses or risks identified in the provided data, making it a strong choice from a security perspective.
oEmbed Plus Security Vulnerabilities
oEmbed Plus Code Analysis
Output Escaping
oEmbed Plus Attack Surface
WordPress Hooks 3
Maintenance & Trust
oEmbed Plus Maintenance & Trust
Maintenance Signals
Community Trust
oEmbed Plus Alternatives
Embed social media
embed-social-media
Simple facebook and instagram embeds without app registration. Just install and activate plugin. Open facebook and instagram oEmbed API was deprecate …
Spotlight Social Feeds – Block, Shortcode, and Widget
spotlight-social-photo-feeds
Instagram feeds made easy. Responsive, customizable, accessible, and SEO-friendly out of the box. Includes Instagram blocks & oEmbed support.
Kliken: Ads + Pixel for Meta
kliken-ads-pixel-for-meta
Drive Sales on Facebook and Instagram in 5 minutes—upload your catalog, implement the Meta Pixel & Conversions API, and grow via Meta Advantage+ now.
All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements
mystickyelements
Get leads with a floating contact form tab, chat & social buttons like Facebook Messenger, WhatsApp, Viber, Telegram, Twitter, Instagram & more 🎉
Easy Social Feed – Social Photos Gallery and Post Feed for WordPress
easy-facebook-likebox
Display Instagram, Facebook & YouTube feeds with photos, videos, reels, events & galleries. Fast, responsive & easy to set up.
oEmbed Plus Developer Profile
7 plugins · 8K total installs
How We Detect oEmbed Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oembed-plus/src/js/admin.js/wp-content/plugins/oembed-plus/src/css/admin.css/wp-content/plugins/oembed-plus/src/js/admin.js