
WP Scribd Security & Risk Analysis
wordpress.org/plugins/wp-scribdDescription: Add Scribd docs inside a post
Is WP Scribd Safe to Use in 2026?
Generally Safe
Score 85/100WP Scribd has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-scribd" v0.1 plugin presents a mixed security picture. On the positive side, it has a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are prepared, and there are no known vulnerabilities (CVEs) associated with it, suggesting a potentially stable and well-maintained past. This indicates a good understanding of fundamental WordPress security practices in these areas.
However, significant concerns arise from the code analysis. A critical weakness is that 100% of its three output operations are not properly escaped. This leaves the plugin highly susceptible to Cross-Site Scripting (XSS) attacks, where malicious code could be injected into content displayed to users. Additionally, the taint analysis reveals two flows with unsanitized paths, which, although not classified as critical or high severity in this specific scan, represent potential entry points for malicious data manipulation if not handled with proper sanitization. The complete absence of nonce checks and capability checks for any potential (though currently non-existent) entry points is also a notable oversight, as these are crucial for protecting against CSRF and unauthorized actions.
In conclusion, while the plugin demonstrates strengths in avoiding common entry points and secure SQL handling, the unescaped output and unsanitized taint flows are serious security flaws that significantly increase its risk profile. The lack of known vulnerabilities is positive but does not negate the immediate risks identified in the static analysis. Users should exercise extreme caution due to the XSS vulnerability.
Key Concerns
- Unescaped output found
- Flows with unsanitized paths found
- No nonce checks implemented
- No capability checks implemented
WP Scribd Security Vulnerabilities
WP Scribd Release Timeline
WP Scribd Code Analysis
Output Escaping
Data Flow Analysis
WP Scribd Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP Scribd Maintenance & Trust
Maintenance Signals
Community Trust
WP Scribd Alternatives
PDF Embedder
pdf-embedder
Seamlessly embed PDFs into your content, with customizations and intelligent responsive resizing, and no third-party services or iframes.
Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files
embed-any-document
Embed PDF, DOC, PPT and XLS documents easily on your WordPress website with the help of Google Docs Viewer or Microsoft Office Online.
Document Embedder – Embed PDFs, Word, Excel, and Other Files
document-emberdder
Document Embedder lets you display PDF, DOCX, PPTX, XLSX, and other files in WordPress sites with a responsive viewer and optional download button.
E2Pdf – Export Pdf Tool for WordPress
e2pdf
PDF Builder for CF7, Divi, Elementor Forms, Everest, Fluent, Formidable, Forminator, Gravity, JFB, Ninja, WPForms, WooCommerce, Post Meta, ACF, etc.
Document Gallery
document-gallery
This plugin generates thumbnails for documents and displays them in a gallery-like format for easy sharing.
WP Scribd Developer Profile
3 plugins · 30 total installs
How We Detect WP Scribd
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- Scridb filter--><i>Scridb filter</i>