
REST API Post Embeds Security & Risk Analysis
wordpress.org/plugins/rest-api-post-embedsEmbed posts from your site or others' into your posts and pages.
Is REST API Post Embeds Safe to Use in 2026?
Generally Safe
Score 100/100REST API Post Embeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rest-api-post-embeds" plugin v1.5.2 exhibits a generally strong security posture due to several good practices observed in the static analysis. Notably, all SQL queries are properly prepared, indicating a defense against SQL injection. The plugin also demonstrates excellent output sanitization, with all observed outputs being correctly escaped, which mitigates cross-site scripting (XSS) risks. The absence of dangerous functions, file operations, and critical/high severity taint flows further contributes to its secure design. Furthermore, the plugin's vulnerability history is clean, with no recorded CVEs, suggesting a history of secure development and maintenance.
However, a few areas warrant attention. The plugin lacks nonce checks and capability checks, which are fundamental security mechanisms in WordPress for verifying user intent and authorization. While there are no unprotected entry points identified in the static analysis, the absence of these checks means that any identified entry points (like the shortcode) could potentially be exploited by an authenticated user without proper validation. The presence of external HTTP requests, while not inherently insecure, could be a vector if the external endpoints are compromised or misconfigured. The lack of any taint analysis results is unusual, and while it might indicate the absence of exploitable flows, it could also be an artifact of the analysis limitations rather than a true absence of risk.
In conclusion, the "rest-api-post-embeds" plugin v1.5.2 is largely secure, adhering to several best practices. Its clean vulnerability history is a significant positive. The primary concern lies in the absence of nonce and capability checks, which, despite a currently low attack surface without authentication, represent a potential weakness that could be exploited in conjunction with future or unforeseen functionalities. The lack of taint analysis results should be noted as a potential area for further investigation if more detailed analysis capabilities were available.
Key Concerns
- Missing nonce checks
- Missing capability checks
- 0 flows analyzed by Taint Analysis
REST API Post Embeds Security Vulnerabilities
REST API Post Embeds Code Analysis
SQL Query Safety
Output Escaping
REST API Post Embeds Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
REST API Post Embeds Maintenance & Trust
Maintenance Signals
Community Trust
REST API Post Embeds Alternatives
Init View Count – AI-Powered, Trending, REST API
init-view-count
Count post views accurately via REST API with customizable display. Lightweight, fast, and extensible. Includes shortcode with multiple layouts.
Challonge
challonge
Integrates Challonge, a handy bracket generator, into WordPress.
OS HTML5 Shortcodes
os-html5-shortcodes
Using shortcodes you can easily add HTML codes such as ad codes, javascript, video embedding, etc in your pages, posts or custom posts.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
REST API Post Embeds Developer Profile
11 plugins · 2K total installs
How We Detect REST API Post Embeds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rest-api-post-embeds/style.cssrest-api-post-embeds/style.css?ver=HTML / DOM Fingerprints
jeherve-post-embedsjeherve-post-embeds-headlinepost-embed-post-titlepost-embed-post-thumbnailpost-embed-post-excerptpost-embed-post-metapost-embed-post-datepost-embed-post-creditsdata-post-embed/wp-json/wp/v2/<div class="jeherve-post-embeds<h3 class="jeherve-post-embeds-headline">