Sermon Embed Security & Risk Analysis

wordpress.org/plugins/soundfaith-embed

Usage

40 active installs v1.2.2 PHP + WP 3.0.1+ Updated Mar 5, 2021
audiochurchembedsermon
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sermon Embed Safe to Use in 2026?

Generally Safe

Score 85/100

Sermon Embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of the "soundfaith-embed" v1.2.2 plugin indicates a strong adherence to secure coding practices. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, or external HTTP requests is highly commendable. Furthermore, the plugin demonstrates a robust approach by not exposing any AJAX handlers, REST API routes, shortcodes, or cron events, thus minimizing its attack surface significantly. The lack of any recorded vulnerabilities in its history reinforces this positive security posture.

However, a critical observation is the complete absence of any nonce checks and capability checks. While the plugin's current design doesn't immediately expose vulnerabilities due to its limited attack surface, this omission represents a significant potential weakness. If future updates introduce new functionalities that expose entry points or if the plugin's dependencies change, the lack of these fundamental security measures could lead to serious vulnerabilities like Cross-Site Request Forgery (CSRF) or unauthorized actions.

In conclusion, the "soundfaith-embed" v1.2.2 plugin exhibits excellent basic security hygiene in its current form, with no evident code-level vulnerabilities or historical security issues. The primary concern lies in the deliberate omission of nonce and capability checks, which, while not exploitable in the current version, leaves the plugin susceptible to future security risks should its functionality expand. The plugin's strengths lie in its minimalist attack surface and clean code, but its weakness is the missing foundational security checks.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Sermon Embed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Sermon Embed Release Timeline

v1.2.2Current
v1.2.1
v1.2.0
v1.1.0
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Sermon Embed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Sermon Embed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuinc\soundfaith-embed-admin.php:12
actionadmin_initinc\soundfaith-embed-admin.php:13
actioninitsoundfaith-embed.php:73
Maintenance & Trust

Sermon Embed Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 5, 2021
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Sermon Embed Developer Profile

eriktdesign

2 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sermon Embed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/soundfaith-embed/inc/css/sf-embed-admin.css/wp-content/plugins/soundfaith-embed/inc/js/sf-embed-admin.js
Script Paths
/wp-content/plugins/soundfaith-embed/inc/js/sf-embed-admin.js
Version Parameters
soundfaith-embed/inc/css/sf-embed-admin.css?ver=soundfaith-embed/inc/js/sf-embed-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wrap
HTML Comments
Generated by the WordPress Option Page generator at http://jeremyhixon.com/wp-tools/option-page/
Data Attributes
data-sermon-detailsdata-include-playlistdata-include-thumbnaildata-include-speakerdata-include-seriesdata-include-date-presented
JS Globals
SF_Embed_Admin
Shortcode Output
<iframe frameborder="0" scrolling="no" allowfullscreen src="https://sermons.faithlife.com/embed/" width="
FAQ

Frequently Asked Questions about Sermon Embed