
OpenGraph Fallback Embed Security & Risk Analysis
wordpress.org/plugins/opengraph-fallback-embedProvides an embed block and auto-embed fallback based on a site's OpenGraph tags when no other embed handler matches the URL.
Is OpenGraph Fallback Embed Safe to Use in 2026?
Generally Safe
Score 100/100OpenGraph Fallback Embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "opengraph-fallback-embed" v1.3.7 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean taint analysis report are significant positive indicators. The code adheres to several WordPress security best practices, including 100% of SQL queries using prepared statements and 100% of output being properly escaped. Furthermore, all identified entry points (REST API) are protected by permission callbacks, and there's at least one capability check present.
However, a few areas warrant attention. The lack of nonce checks, even with a limited attack surface, is a potential concern. While there are no directly exploitable vulnerabilities indicated by the taint analysis, the presence of file operations and external HTTP requests, especially without explicit mention of sanitization or validation related to them in the provided data, could theoretically introduce risks if not handled with extreme care.
Overall, the plugin appears to be well-developed from a security perspective, with no historical vulnerabilities and good adherence to core security principles. The primary areas for improvement lie in implementing nonce checks for any potential future dynamic interactions and ensuring robust validation around the file operation and external HTTP request functionalities.
Key Concerns
- Missing nonce checks on entry points
- Presence of file operations without explicit sanitization checks
- Presence of external HTTP requests without explicit sanitization checks
OpenGraph Fallback Embed Security Vulnerabilities
OpenGraph Fallback Embed Release Timeline
OpenGraph Fallback Embed Code Analysis
Output Escaping
OpenGraph Fallback Embed Attack Surface
REST API Routes 1
WordPress Hooks 7
Maintenance & Trust
OpenGraph Fallback Embed Maintenance & Trust
Maintenance Signals
Community Trust
OpenGraph Fallback Embed Alternatives
Simple Link Embed
simple-link-embed
Create beautiful blog cards by simply entering a URL. Automatically fetches OGP data and displays stylish link previews in the block editor.
Simple Blog Card
simple-blog-card
Get OGP and display blog card.
Bookmark Card
bookmark-card
Turn any URL into a beautiful preview card.
WWI Blogcard
wwi-blogcard
A WordPress block plugin that generates beautiful blog cards from URLs using OGP information.
PDF Embedder
pdf-embedder
Seamlessly embed PDFs into your content, with customizations and intelligent responsive resizing, and no third-party services or iframes.
OpenGraph Fallback Embed Developer Profile
4 plugins · 31K total installs
How We Detect OpenGraph Fallback Embed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/opengraph-fallback-embed/build/og-embed/style-index.cssHTML / DOM Fingerprints
og-fallback-embed__error/og-fallback-embed/v1/preview