Wiki Embed Security & Risk Analysis

wordpress.org/plugins/wiki-embed

Wiki Embed lets you embed mediawiki pages in to your site, sites like Wikipedia

100 active installs v1.4.10 PHP + WP 3.0+ Updated May 2, 2025
content-frameworkembedmediawikiwikiwiki-embed
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 7, 2025
Safety Verdict

Is Wiki Embed Safe to Use in 2026?

Generally Safe

Score 99/100

Wiki Embed has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 7, 2025Updated 11mo ago
Risk Assessment

The wiki-embed plugin v1.4.10 exhibits a generally good security posture with several strong points, including 100% output escaping and a complete absence of dangerous functions or file operations. The plugin also demonstrates a solid use of nonces and capability checks throughout its code. However, there are significant concerns, particularly regarding its attack surface. Two AJAX handlers lack authentication checks, presenting a direct entry point for potentially unauthorized actions. The taint analysis reveals one flow with an unsanitized path, which, while not currently classified as critical or high severity, indicates a potential for issues if malicious input is not handled rigorously. The vulnerability history shows one medium severity CVE in the past, a CSRF vulnerability, which suggests that while significant vulnerabilities have been addressed, the possibility of similar issues in the future or related security weaknesses cannot be entirely dismissed.

Key Concerns

  • AJAX handlers without authentication
  • Flow with unsanitized paths
  • Past medium severity CVE
Vulnerabilities
1

Wiki Embed Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-47551medium · 4.3Cross-Site Request Forgery (CSRF)

Wiki Embed <= 1.4.6 - Cross-Site Request Forgery

May 7, 2025 Patched in 1.4.7 (7d)
Code Analysis
Analyzed Mar 16, 2026

Wiki Embed Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
4
96 escaped
Nonce Checks
7
Capability Checks
9
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

96% escaped100 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

6 flows1 with unsanitized paths
<WikiEmbed> (WikiEmbed.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Wiki Embed Attack Surface

Entry Points7
Unprotected2

AJAX Handlers 6

authwp_ajax_wiki_embedWikiEmbed.php:212
noprivwp_ajax_wiki_embedWikiEmbed.php:214
authwp_ajax_wiki_embed_add_linkWikiEmbed.php:1495
authwp_ajax__nopriv_wiki_embed_add_linkWikiEmbed.php:1496
authwp_ajax_wiki_embed_remove_linkWikiEmbed.php:1499
authwp_ajax__nopriv_wiki_embed_remove_linkWikiEmbed.php:1500

Shortcodes 1

[wiki-embed] WikiEmbed.php:205
WordPress Hooks 19
actionadmin_footeradmin\admin-overlay.php:4
actionmedia_buttons_contextadmin\admin-overlay.php:5
actionadmin_initadmin\admin.php:4
actionadmin_menuadmin\admin.php:5
actionwpmu_optionsadmin\admin.php:7
actionupdate_wpmu_optionsadmin\admin.php:10
actionplugins_loadedpast\wiki-embed-update.php:12
filterwiki-embed-tab_listsupport\twitter-bootstrap\action.php:9
filterwiki-embed-articlessupport\twitter-bootstrap\action.php:10
filterwiki-embed-article-contentsupport\twitter-bootstrap\action.php:11
filterwiki-embed-article-content-classsupport\twitter-bootstrap\action.php:12
filterwiki-embed-tabs-shell-classsupport\twitter-bootstrap\action.php:13
actioninitWikiEmbed.php:82
actiontemplate_redirectWikiEmbed.php:91
filterposts_joinWikiEmbed.php:92
filterposts_whereWikiEmbed.php:93
filtersf_posts_queryWikiEmbed.php:94
filterpage_linkWikiEmbed.php:198
actionwp_footerWikiEmbed.php:207
Maintenance & Trust

Wiki Embed Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedMay 2, 2025
PHP min version
Downloads16K

Community Trust

Rating76/100
Number of ratings8
Active installs100
Developer Profile

Wiki Embed Developer Profile

ctltwp

15 plugins · 6K total installs

77
trust score
Avg Security Score
84/100
Avg Patch Time
34 days
View full developer profile
Detection Fingerprints

How We Detect Wiki Embed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wiki-embed/resources/js/tabs.js/wp-content/plugins/wiki-embed/resources/js/accordion.js/wp-content/plugins/wiki-embed/resources/js/anchor-links.js/wp-content/plugins/wiki-embed/support/twitter-bootstrap/twitter.bootstrap.tabs.js/wp-content/plugins/wiki-embed/resources/css/tabs.css/wp-content/plugins/wiki-embed/resources/css/accordion.css/wp-content/plugins/wiki-embed/resources/css/wiki-embed.css/wp-content/plugins/wiki-embed/resources/js/jquery.colorbox.min.js+3 more
Script Paths
/wiki-embed/resources/js/tabs.js/wiki-embed/resources/js/accordion.js/wiki-embed/resources/js/anchor-links.js/wiki-embed/support/twitter-bootstrap/twitter.bootstrap.tabs.js/wiki-embed/resources/js/jquery.colorbox.min.js/wiki-embed/resources/js/overlay.js+1 more
Version Parameters
wiki-embed/resources/js/tabs.js?ver=wiki-embed/resources/js/accordion.js?ver=wiki-embed/resources/js/anchor-links.js?ver=wiki-embed/support/twitter-bootstrap/twitter.bootstrap.tabs.js?ver=wiki-embed/resources/js/jquery.colorbox.min.js?ver=wiki-embed/resources/js/overlay.js?ver=wiki-embed/resources/js/new-page.js?ver=

HTML / DOM Fingerprints

CSS Classes
wiki-embedwiki-embed-content
HTML Comments
WikiEmbed - embed multiple mediawiki page into your post or pageCopyright (C) 2008, OLT, www.olt.ubc.comAll rights reserved.
Data Attributes
data-wiki-embed-urldata-wiki-embed-titledata-wiki-embed-language
JS Globals
WikiEmbedSettings
Shortcode Output
[wikiembed][/wikiembed]
FAQ

Frequently Asked Questions about Wiki Embed