WB Embed Code Security & Risk Analysis

wordpress.org/plugins/wb-embed-code

A simple plugin created by the WP Bucket plugin for embed bitbucket codes in the wordpress posts with shortcode.

10 active installs v0.1.0 PHP + WP 3.6+ Updated Mar 10, 2014
apibitbucketoauthrestwp_remote_request
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WB Embed Code Safe to Use in 2026?

Generally Safe

Score 85/100

WB Embed Code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The wb-embed-code plugin version 0.1.0 exhibits a generally good security posture based on the provided static analysis. It adheres to best practices by exclusively using prepared statements for SQL queries and properly escaping all outputs. The absence of file operations and external HTTP requests further reduces potential attack vectors. Furthermore, the plugin has no recorded vulnerability history, indicating a lack of publicly known security flaws.

However, the static analysis does highlight a potential area of concern: the complete absence of nonce checks and capability checks. While the current entry points are minimal (only one shortcode) and there are no AJAX handlers or REST API routes exposed without authorization, this reliance on the absence of other attack surfaces is precarious. Should future updates introduce new entry points or modify existing ones without implementing these crucial security measures, the plugin could become vulnerable to various attacks, such as Cross-Site Request Forgery (CSRF) or privilege escalation.

In conclusion, the plugin's current implementation is secure due to its limited functionality and adherence to basic secure coding principles. The primary weakness lies in the lack of explicit security checks like nonces and capability checks, which, while not exploitable in the current version, represent a significant potential risk for future development and warrant attention to maintain a robust security profile.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

WB Embed Code Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WB Embed Code Release Timeline

vv0.1.1
Code Analysis
Analyzed Apr 16, 2026

WB Embed Code Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

WB Embed Code Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bitbucket] wb-embed-code.php:72
WordPress Hooks 1
actionwprest_http_requestwb-embed-code.php:25
Maintenance & Trust

WB Embed Code Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedMar 10, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WB Embed Code Developer Profile

Hadi khosrojerdi

3 plugins · 120 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WB Embed Code

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<pre>
FAQ

Frequently Asked Questions about WB Embed Code