
Wonder PDF Embed Security & Risk Analysis
wordpress.org/plugins/wonderplugin-pdf-embedEmbed PDF to your WordPress website by using Mozilla's PDF.js
Is Wonder PDF Embed Safe to Use in 2026?
Generally Safe
Score 100/100Wonder PDF Embed has a strong security track record. Known vulnerabilities have been patched promptly.
The "wonderplugin-pdf-embed" plugin version 3.1 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, the use of prepared statements for all SQL queries, and proper output escaping are commendable practices. Furthermore, the presence of a nonce check and the limited attack surface with no immediately unprotected entry points suggest a level of security awareness in its development.
However, the analysis does reveal some areas of concern. Specifically, the taint analysis indicates two flows with unsanitized paths, although they are not categorized as critical or high severity. This suggests a potential for input sanitation issues that could be exploited under certain conditions. The vulnerability history, while showing no currently unpatched CVEs, does list one past medium-severity vulnerability related to Cross-Site Scripting. This historical pattern warrants attention, as it points to a past weakness that, even if resolved, indicates a propensity for certain types of vulnerabilities.
In conclusion, while the plugin demonstrates strong fundamental security practices in its current version, the presence of unsanitized paths in taint flows and the historical XSS vulnerability suggest that careful code review and ongoing vigilance are still necessary. The lack of capability checks on its entry points also represents a missed opportunity for more robust access control.
Key Concerns
- Taint flows with unsanitized paths (2)
- Past medium severity XSS vulnerability
- No capability checks on entry points
Wonder PDF Embed Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Wonder PDF Embed <= 1.6 - Contributor+ Stored Cross-Site Scripting
Wonder PDF Embed Code Analysis
Output Escaping
Data Flow Analysis
Wonder PDF Embed Attack Surface
Shortcodes 2
WordPress Hooks 2
Maintenance & Trust
Wonder PDF Embed Maintenance & Trust
Maintenance Signals
Community Trust
Wonder PDF Embed Alternatives
PDF Poster – Display PDF Files with Custom Viewer
pdf-poster
PDF Poster lets you embed PDF files in WordPress using a responsive viewer and block support, including full-screen, download, and print options.
Real 3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder
real3d-flipbook-lite
Embed PDF files easily anywhere on your website. Display your PDFs and images as stunning, interactive 3D flipbooks directly within WordPress.
Algori PDF Viewer
algori-pdf-viewer
Algori PDF Viewer is a Gutenberg Block Plugin that enables you to easily display PDF documents directly on your website.
Quick Embed PDF – PDF viewer, PDF embeds, PDF Reader, PDF Embedder
quick-embed-pdf
Quickly embed and display (viewer) PDF files in WordPress posts and pages using a simple shortcode or Gutenberg block.
MagicFlip
magicflip
MagicFlip - simple PDF viewer plugin for WordPress
Wonder PDF Embed Developer Profile
6 plugins · 26K total installs
How We Detect Wonder PDF Embed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wonderplugin-pdf-embed/pdfjslight/web/viewer.html/wp-content/plugins/wonderplugin-pdf-embed/pdfjs/web/viewer.htmlHTML / DOM Fingerprints
wonderplugin-pdf-iframedata-wonderplugin-pdf-embedwonder_pdf_optionswonder_pdf_embed_options<iframe class="wonderplugin-pdf-iframe" src="