
PDF Poster – Display PDF Files with Custom Viewer Security & Risk Analysis
wordpress.org/plugins/pdf-posterPDF Poster lets you embed PDF files in WordPress using a responsive viewer and block support, including full-screen, download, and print options.
Is PDF Poster – Display PDF Files with Custom Viewer Safe to Use in 2026?
Generally Safe
Score 100/100PDF Poster – Display PDF Files with Custom Viewer has a strong security track record. Known vulnerabilities have been patched promptly.
The 'pdf-poster' plugin v2.5.0 exhibits a mixed security posture. While it demonstrates good practices in output escaping and avoids dangerous functions and file operations, there are significant areas of concern. The presence of an unprotected AJAX handler represents a critical entry point that could be exploited by attackers if not properly secured. Additionally, all SQL queries lack prepared statements, which significantly increases the risk of SQL injection vulnerabilities. The plugin's vulnerability history shows a past medium-severity Cross-Site Scripting (XSS) vulnerability, indicating that input sanitization has been an issue, and the absence of any taint analysis data makes it difficult to assess the current risk of such flaws. Despite its strengths in output escaping, the unprotected AJAX handler and the complete lack of SQL preparedness are substantial weaknesses that warrant attention.
Key Concerns
- Unprotected AJAX handler
- SQL queries not using prepared statements
- Past medium severity XSS vulnerability
PDF Poster – Display PDF Files with Custom Viewer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
PDF Poster - PDF Embedder Plugin for WordPress <= 2.1.17 - Reflected Cross-Site Scripting
PDF Poster – Display PDF Files with Custom Viewer Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
PDF Poster – Display PDF Files with Custom Viewer Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 34
Maintenance & Trust
PDF Poster – Display PDF Files with Custom Viewer Maintenance & Trust
Maintenance Signals
Community Trust
PDF Poster – Display PDF Files with Custom Viewer Alternatives
PDF Embedder
pdf-embedder
Seamlessly embed PDFs into your content, with customizations and intelligent responsive resizing, and no third-party services or iframes.
Document Embedder – Embed PDFs, Word, Excel, and Other Files
document-emberdder
Document Embedder lets you display PDF, DOCX, PPTX, XLSX, and other files in WordPress sites with a responsive viewer and optional download button.
Pdf Embed
pdf-embed
PDF embedder with official Adobe Embed API.
Real 3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder
real3d-flipbook-lite
Embed PDF files easily anywhere on your website. Display your PDFs and images as stunning, interactive 3D flipbooks directly within WordPress.
Algori PDF Viewer
algori-pdf-viewer
Algori PDF Viewer is a Gutenberg Block Plugin that enables you to easily display PDF documents directly on your website.
PDF Poster – Display PDF Files with Custom Viewer Developer Profile
120 plugins · 738K total installs
How We Detect PDF Poster – Display PDF Files with Custom Viewer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pdf-poster/build/dashboard.css/wp-content/plugins/pdf-poster/build/dashboard.js/wp-content/plugins/pdf-poster/build/dashboard.jspdf-poster/build/dashboard.css?ver=pdf-poster/build/dashboard.js?ver=HTML / DOM Fingerprints
pdfp_insert_pdf_btndata-dirpdfpDashboardtokenClientaccessTokenpickerInitedgisInited