Rajce embed Security & Risk Analysis

wordpress.org/plugins/rajce-embed

Embeds photos and photo-albums stored on rajce.net as native WordPress galleries

30 active installs v1.5.1 PHP + WP 4.0+ Updated Jan 13, 2016
embedgalleryimageimagesoembed
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Rajce embed Safe to Use in 2026?

Generally Safe

Score 85/100

Rajce embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The rajce-embed v1.5.1 plugin exhibits a generally positive security posture based on the provided static analysis. The complete absence of entry points (AJAX handlers, REST API routes, shortcodes, cron events) significantly limits the plugin's attack surface. Furthermore, the reliance on prepared statements for all SQL queries and the lack of dangerous function usage are strong indicators of secure coding practices in these areas. The vulnerability history also shows no known CVEs, which suggests a history of security awareness or a lack of discoverable vulnerabilities.

However, there are notable areas of concern. The low percentage of properly escaped output (17%) is a significant weakness. This indicates that a substantial portion of data rendered to the user might be susceptible to Cross-Site Scripting (XSS) attacks, especially if the plugin handles user-supplied or dynamic data without adequate sanitization before outputting it.

In conclusion, while the plugin's minimal attack surface and secure SQL handling are commendable, the prevalent issue of unescaped output presents a clear security risk. The lack of any recorded vulnerabilities in its history is a positive sign, but it does not mitigate the immediate risk posed by the output escaping issues. Developers should prioritize addressing the output escaping deficiencies to improve the plugin's overall security.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Rajce embed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Rajce embed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

17% escaped6 total outputs
Attack Surface

Rajce embed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_initrajce-embed.php:20
actionwp_enqueue_scriptsrajce-embed.php:21
actionadmin_initwp-rajce.php:20
actioninitwp-rajce.php:22
filterthe_contentwp-rajce.php:34
actionadmin_noticeswp-rajce.php:49
actionadmin_noticeswp-rajce.php:51
Maintenance & Trust

Rajce embed Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedJan 13, 2016
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Rajce embed Developer Profile

honza.skypala

5 plugins · 610 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Rajce embed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rajce-embed/css/html5-gallery.css/wp-content/plugins/rajce-embed/css/dl-dt-gallery.css/wp-content/plugins/rajce-embed/css/mini-preview.css
Script Paths
/wp-content/plugins/rajce-embed/mini-preview.js
Version Parameters
rajce-embed/css/html5-gallery.css?ver=rajce-embed/css/dl-dt-gallery.css?ver=rajce-embed/css/mini-preview.css?ver=rajce-embed/mini-preview.js?ver=

HTML / DOM Fingerprints

CSS Classes
rajce-embed-gallery-itemrajce-embed-gallery-item-caption
Data Attributes
data-rajce-id
JS Globals
jQuery
Shortcode Output
[rajce][rajce-gallery]
FAQ

Frequently Asked Questions about Rajce embed