
WP-Git-Embed Security & Risk Analysis
wordpress.org/plugins/wp-git-embedEmbed GitHub, Gist or Bitbucket files.
Is WP-Git-Embed Safe to Use in 2026?
Generally Safe
Score 100/100WP-Git-Embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-git-embed plugin v0.4 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, coupled with the fact that all SQL queries utilize prepared statements and all output is properly escaped, are significant strengths. Furthermore, the plugin demonstrates a small attack surface with zero entry points identified, which is commendable. However, there are some notable concerns. The presence of two instances of `preg_replace(/e)` is a red flag, as this function is known to be dangerous and can be exploited for remote code execution if not handled with extreme care and proper sanitization. The plugin also lacks nonce checks and capability checks, which are crucial for preventing various types of attacks, especially if any of the entry points were to become exposed or if new ones are added in future versions. The file operation, while only one, is another area that warrants attention due to potential security implications if not implemented securely. In conclusion, while the plugin has a clean history and good practices in many areas, the identified dangerous functions and missing security checks represent potential vulnerabilities that should be addressed.
Key Concerns
- Dangerous function: preg_replace(/e)
- Missing nonce checks
- Missing capability checks
- File operations without specific security context
WP-Git-Embed Security Vulnerabilities
WP-Git-Embed Code Analysis
Dangerous Functions Found
WP-Git-Embed Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP-Git-Embed Maintenance & Trust
Maintenance Signals
Community Trust
WP-Git-Embed Alternatives
WP Github Gist
wp-github-gist
Embed files and gist from Github in your blog posts or pages.
Gist for Robots WordPress Plugin
gist-for-robots-wordpress
Makes embedding Github.com gists SEO friendly and super awesomely easy.
GitHub Gist WordPress Plugin
github-gist
GitHub Gist Wordpress Plugin allows you to embed GitHub Gist snippets with a [gist] tag, instead of copying and pasting HTML.
PCSH (PastaCode and SyntaxHighlighter)
pcsh-pastacode-syntaxhighlighter
Use PCSH to add code into your posts with the awesome SyntaxHighlighter plugin. So, past'a code!
Simple Gist Embed
simple-gist-embed
This plugin lets you embed Github's Gists in your posts or pages, but the main deference is that this plugin also enables you to create Gists wit …
WP-Git-Embed Developer Profile
2 plugins · 110 total installs
How We Detect WP-Git-Embed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wp-git-embed<div class="wp-git-embed"view rawview file on<strong>GitHub</strong>