RV Embed PDF Security & Risk Analysis

wordpress.org/plugins/rv-embed-pdf

Embeds a PDF in your page or post when you insert it with the Add Media button.

900 active installs v1.1 PHP + WP 3.5+ Updated Sep 25, 2015
add-mediaembedgoogle-docs-viewerpdfupload
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is RV Embed PDF Safe to Use in 2026?

Generally Safe

Score 85/100

RV Embed PDF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the 'rv-embed-pdf' plugin v1.1 presents a remarkably low security risk. The static analysis indicates a clean codebase with no identified dangerous functions, no direct SQL queries (all are prepared statements), and all output is properly escaped. Furthermore, there are no file operations or external HTTP requests, and critically, no discernible attack surface through common WordPress entry points like AJAX handlers, REST API routes, or shortcodes that are not protected by capability checks or nonces. The absence of any known CVEs and a clean vulnerability history further bolsters this assessment.

While the lack of identified vulnerabilities and a clean code profile are strong indicators of good security practices, the static analysis does note a complete absence of nonce checks and capability checks across all entry points. In a scenario where entry points were present, this would be a significant concern. However, given that the attack surface is reported as zero, this observation appears to be a consequence of there being no actual points of entry to check, rather than an oversight in implementing checks where they would be needed. The plugin demonstrates a proactive approach to security by avoiding risky functionalities and potential vulnerabilities altogether.

Vulnerabilities
None known

RV Embed PDF Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RV Embed PDF Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

RV Embed PDF Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filtermedia_send_to_editorrv_embedpdf.php:22
Maintenance & Trust

RV Embed PDF Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedSep 25, 2015
PHP min version
Downloads39K

Community Trust

Rating72/100
Number of ratings9
Active installs900
Developer Profile

RV Embed PDF Developer Profile

premek.v

1 plugin · 900 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RV Embed PDF

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<iframe src="http://docs.google.com/gview?url=&embedded=true" style="width:100%; height:500px;" frameborder="0"></iframe>
FAQ

Frequently Asked Questions about RV Embed PDF