
WP Calameo Security & Risk Analysis
wordpress.org/plugins/wp-calameoThis plugin allows to embed Calaméo publications in blog posts. Copy the WordPress embed code and paste it into your post.
Is WP Calameo Safe to Use in 2026?
Generally Safe
Score 85/100WP Calameo has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of wp-calameo v2.1.8 reveals a generally strong security posture with good coding practices. All identified SQL queries use prepared statements, and all output is properly escaped, indicating a proactive approach to preventing common web vulnerabilities. The limited attack surface, consisting of a single shortcode and no unprotected entry points, is also a positive sign. There are no identified dangerous functions, file operations, external HTTP requests, or bundled libraries that could pose a risk. The taint analysis showing zero flows with unsanitized paths further reinforces this positive assessment.
Key Concerns
- Medium severity CVE in vulnerability history
- Vulnerability history indicates XSS as a common type
- No nonce checks on entry points
- No capability checks on entry points
WP Calameo Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Calameo <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Calameo Code Analysis
Output Escaping
WP Calameo Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
WP Calameo Maintenance & Trust
Maintenance Signals
Community Trust
WP Calameo Alternatives
Manage Calameo Publications by Athlon
athlon-manage-calameo-publications
This plugin allows managing Calameo account(s) through WordPress.
YouScribe
youscribe
This plugin allows to embed YouScribe publications in blog posts using Open Embed.
PDF Embedder
pdf-embedder
Seamlessly embed PDFs into your content, with customizations and intelligent responsive resizing, and no third-party services or iframes.
Spotlight Social Feeds – Block, Shortcode, and Widget
spotlight-social-photo-feeds
Instagram feeds made easy. Responsive, customizable, accessible, and SEO-friendly out of the box. Includes Instagram blocks & oEmbed support.
Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files
embed-any-document
Embed PDF, DOC, PPT and XLS documents easily on your WordPress website with the help of Google Docs Viewer or Microsoft Office Online.
WP Calameo Developer Profile
1 plugin · 3K total installs
How We Detect WP Calameo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
calameoallowminiskinauthidapikeyclicktoclicktarget+23 more<div style="text-align: center; width:<a href="http://calameo.com/books/<iframe src="//v.calameo.com/?bkcode=<a rel="nofollow" href="http://calameo.com/upload">Publish</a> at <a href="http://calameo.com">Calaméo</a> or <a href="http://calameo.com/browse/weekly/?o=7&w=DESC">browse</a> the library.