Radeet pdf Embed Security & Risk Analysis

wordpress.org/plugins/radeet-pdf-embed

Embeds PDFs in your pages and posts, without using JS.

100 active installs v2.3.0 PHP + WP 3.0.1+ Updated Feb 22, 2017
embedpdf
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Radeet pdf Embed Safe to Use in 2026?

Generally Safe

Score 85/100

Radeet pdf Embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The plugin 'radeet-pdf-embed' v2.3.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals excellent adherence to secure coding practices, with all identified SQL queries utilizing prepared statements and all output being properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a reduced attack surface. The plugin also lacks any known vulnerabilities, with zero recorded CVEs, indicating a history of stable and secure development.

While the plugin demonstrates good security fundamentals, a potential area for improvement lies in the absence of nonce checks and capability checks. Although the current attack surface is minimal (one shortcode with no identified unprotected entry points), these checks are crucial for preventing unauthorized actions and ensuring the integrity of plugin functionality, especially as plugins evolve or new entry points are introduced. The lack of taint analysis results also makes it difficult to definitively rule out complex vulnerabilities that might not be caught by simpler code signals.

Overall, 'radeet-pdf-embed' v2.3.0 appears to be a secure plugin with a commendable track record. The strengths lie in its secure SQL handling, output escaping, and lack of known vulnerabilities. The primary weakness, though not an immediate critical threat given the current limited attack surface, is the absence of nonce and capability checks, which represent a best practice for enhanced security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Radeet pdf Embed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Radeet pdf Embed Release Timeline

v2.3.0Current
v2.2.0
v2.1.0
v2.0
v2.0.0
Code Analysis
Analyzed Mar 16, 2026

Radeet pdf Embed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

100% escaped4 total outputs
Attack Surface

Radeet pdf Embed Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[pdf] radeet-pdf-embed.php:104
WordPress Hooks 1
filterwp_get_attachment_linkradeet-pdf-embed.php:155
Maintenance & Trust

Radeet pdf Embed Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedFeb 22, 2017
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Radeet pdf Embed Developer Profile

A. H. M. Anawar Parvez

2 plugins · 300 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Radeet pdf Embed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/radeet-pdf-embed/css/style.css

HTML / DOM Fingerprints

CSS Classes
radeet-pdf-embed
Data Attributes
data-src
Shortcode Output
[pdf
FAQ

Frequently Asked Questions about Radeet pdf Embed