
Sermon Embed Security & Risk Analysis
wordpress.org/plugins/soundfaith-embedUsage
Is Sermon Embed Safe to Use in 2026?
Generally Safe
Score 85/100Sermon Embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "soundfaith-embed" v1.2.2 plugin indicates a strong adherence to secure coding practices. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, or external HTTP requests is highly commendable. Furthermore, the plugin demonstrates a robust approach by not exposing any AJAX handlers, REST API routes, shortcodes, or cron events, thus minimizing its attack surface significantly. The lack of any recorded vulnerabilities in its history reinforces this positive security posture.
However, a critical observation is the complete absence of any nonce checks and capability checks. While the plugin's current design doesn't immediately expose vulnerabilities due to its limited attack surface, this omission represents a significant potential weakness. If future updates introduce new functionalities that expose entry points or if the plugin's dependencies change, the lack of these fundamental security measures could lead to serious vulnerabilities like Cross-Site Request Forgery (CSRF) or unauthorized actions.
In conclusion, the "soundfaith-embed" v1.2.2 plugin exhibits excellent basic security hygiene in its current form, with no evident code-level vulnerabilities or historical security issues. The primary concern lies in the deliberate omission of nonce and capability checks, which, while not exploitable in the current version, leaves the plugin susceptible to future security risks should its functionality expand. The plugin's strengths lie in its minimalist attack surface and clean code, but its weakness is the missing foundational security checks.
Key Concerns
- Missing nonce checks
- Missing capability checks
Sermon Embed Security Vulnerabilities
Sermon Embed Release Timeline
Sermon Embed Code Analysis
Sermon Embed Attack Surface
WordPress Hooks 3
Maintenance & Trust
Sermon Embed Maintenance & Trust
Maintenance Signals
Community Trust
Sermon Embed Alternatives
Mattytap Sermons
mattytap-sermons
A maintained restoration of Sermon Manager: publish, organise, and podcast sermons on a WordPress site.
Compact WP Audio Player
compact-wp-audio-player
A Compact WP Audio Player Plugin that is compatible with all major browsers and devices (Android, iPhone, iPad)
Church Content – Sermons, Events and More
church-theme-content
Provides an interface for managing sermons, events, people and locations. A compatible theme is required for presenting content from these church-cent …
Spreaker Shortcode
spreaker-shortcode
A simple and easy way to embed Spreaker player into your WordPress blog.
Advanced Sermons
advanced-sermons
Elevate your church's digital outreach with audio/video sermons, organized speakers, and series management.
Sermon Embed Developer Profile
2 plugins · 40 total installs
How We Detect Sermon Embed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/soundfaith-embed/inc/css/sf-embed-admin.css/wp-content/plugins/soundfaith-embed/inc/js/sf-embed-admin.js/wp-content/plugins/soundfaith-embed/inc/js/sf-embed-admin.jssoundfaith-embed/inc/css/sf-embed-admin.css?ver=soundfaith-embed/inc/js/sf-embed-admin.js?ver=HTML / DOM Fingerprints
wrap Generated by the WordPress Option Page generator at http://jeremyhixon.com/wp-tools/option-page/data-sermon-detailsdata-include-playlistdata-include-thumbnaildata-include-speakerdata-include-seriesdata-include-date-presentedSF_Embed_Admin<iframe frameborder="0" scrolling="no" allowfullscreen src="https://sermons.faithlife.com/embed/" width="