
Noembedder Security & Risk Analysis
wordpress.org/plugins/wp-noembedderAdds noembed tags to any embeded object that doesn't have them
Is Noembedder Safe to Use in 2026?
Generally Safe
Score 85/100Noembedder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-noembedder v1.1 plugin exhibits a generally positive security posture based on the static analysis provided, with no identified dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), or file operations. The absence of external HTTP requests and taint analysis findings also suggests a clean codebase in these critical areas. Furthermore, the plugin has no recorded vulnerabilities or CVEs, indicating a history of secure development or a lack of targeted exploitation. However, a significant concern arises from the complete lack of output escaping. With four identified outputs and none being properly escaped, this presents a substantial risk for Cross-Site Scripting (XSS) vulnerabilities. Any data rendered by the plugin without proper sanitization could be manipulated by an attacker to inject malicious scripts, leading to session hijacking or other harmful actions. The lack of capability checks and nonce checks, while not directly a risk in themselves due to the limited attack surface identified (zero unprotected entry points), signifies a missed opportunity for robust access control if the attack surface were to expand in future versions. Overall, while the plugin is free of common, severe vulnerabilities and has a clean history, the unescaped output is a critical weakness that needs immediate attention.
Key Concerns
- Output escaping missing
Noembedder Security Vulnerabilities
Noembedder Release Timeline
Noembedder Code Analysis
Output Escaping
Noembedder Attack Surface
WordPress Hooks 2
Maintenance & Trust
Noembedder Maintenance & Trust
Maintenance Signals
Community Trust
Noembedder Alternatives
The Ultimate Video Player For WordPress – by Presto Player
presto-player
The Ultimate WordPress Video Player.
Advanced WordPress Backgrounds
advanced-backgrounds
Easy to use advanced Parallax, Image and Video backgrounds block plugin with parallax and video support.
WP YouTube Lyte
wp-youtube-lyte
High performance YouTube video, playlist and audio-only embeds which don't slow down your blog and offer optimal accessibility.
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
Video Popup – Video Lightbox for YouTube, Vimeo & MP4
video-popup
Video Popup plugin lets you create unlimited, responsive Video Lightbox and Popup for YouTube, Vimeo, MP4 & WebM on click or page load.
Noembedder Developer Profile
6 plugins · 80 total installs
How We Detect Noembedder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapoptionseditformname="wp_votd_update"name="info_update"name="cmd"name="business"name="item_name"name="no_note"+3 more<noembed><p><em>There is embedded content here that you cannot see. Please <a href=""><img src="" alt="" /></a><br /><em>There is embedded content here that you cannot see. Please <a href="">open the post in a web browser</a> to see this.</em></p></noembed>