Simple Page Embed Security & Risk Analysis

wordpress.org/plugins/swiftninjapro-facebook-embed

Embed a responsive Facebook page to your website.

10 active installs v1.1.11 PHP 5.2.4+ WP 3.0.1+ Updated Oct 22, 2020
embedfacebookfbresponsivesocial
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Page Embed Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Page Embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The swiftninjapro-facebook-embed plugin, version 1.1.11, exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, critical or high severity taint flows, and the complete reliance on prepared statements for SQL queries are all positive indicators. The plugin also demonstrates good practices by not exposing any AJAX handlers, REST API routes, shortcodes, or cron events directly to user interaction without proper authentication checks, resulting in zero identified entry points without authorization.

However, a significant concern arises from the output escaping. With 59% of outputs properly escaped, there remains a 41% portion that is not. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly in the frontend without adequate sanitization or escaping. While no specific XSS issues were flagged in the taint analysis, this percentage represents a notable risk area that warrants attention. The plugin's lack of nonce checks on its limited capabilities also presents a potential for cross-site request forgery (CSRF) if these capabilities are exploited in conjunction with unescaped output.

Overall, the plugin is well-designed in terms of limiting its attack surface and securing its data interactions. The primary weakness lies in the insufficient output escaping. The absence of historical vulnerabilities is encouraging but should not lead to complacency, especially given the identified output escaping deficiencies. Addressing the unescaped outputs should be the priority to further strengthen the plugin's security.

Key Concerns

  • Insufficient output escaping
  • Lack of nonce checks
Vulnerabilities
None known

Simple Page Embed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Simple Page Embed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
17 escaped
Nonce Checks
0
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

59% escaped29 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
SwiftNinjaPro_settings_GetOption (templates\admin.php:109)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Simple Page Embed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptsswiftninjapro-facebook-embed.php:70
actionadmin_menuswiftninjapro-facebook-embed.php:71
Maintenance & Trust

Simple Page Embed Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 22, 2020
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Simple Page Embed Developer Profile

SwiftNinjaPro

7 plugins · 710 total installs

83
trust score
Avg Security Score
84/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Page Embed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/swiftninjapro-facebook-embed/assets/style.css/wp-content/plugins/swiftninjapro-facebook-embed/assets/script.js
Script Paths
/wp-content/plugins/swiftninjapro-facebook-embed/assets/script.js
Version Parameters
swiftninjapro-facebook-embed/assets/style.css?ver=swiftninjapro-facebook-embed/assets/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
facebook-containerfacebook
Shortcode Output
<div class="facebook-container"><iframe class="facebook" src="https://www.facebook.com/plugins/page.php?href=https%3A%2F%2Fwww.facebook.com%2F
FAQ

Frequently Asked Questions about Simple Page Embed