
WP Wrapper Security & Risk Analysis
wordpress.org/plugins/wp-wrapperWrapper for WordPress pages using iFrame. Various options in admin panel
Is WP Wrapper Safe to Use in 2026?
Generally Safe
Score 92/100WP Wrapper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-wrapper" plugin version 1.2.9 demonstrates a strong security posture based on the provided static analysis. The plugin exhibits a remarkably small attack surface, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events. Crucially, all identified entry points appear to be protected, indicating a commitment to access control. The code also shows good practices regarding SQL queries, exclusively using prepared statements, and a high percentage of properly escaped output.
Despite the generally positive findings, there is one identified flow with an unsanitized path in the taint analysis, which warrants attention. While the severity is not explicitly classified as critical or high, any unsanitized path is a potential risk for directory traversal or other path manipulation vulnerabilities. The plugin's vulnerability history is clean, with no recorded CVEs, which is a significant strength. This suggests a history of secure development and maintenance.
In conclusion, "wp-wrapper" v1.2.9 appears to be a secure plugin with robust development practices. The lack of known vulnerabilities and a well-controlled attack surface are commendable. The single identified unsanitized path is the primary concern and should be investigated and remediated to maintain this strong security record.
Key Concerns
- Flow with unsanitized path found
- Output escaping not fully proper (87%)
WP Wrapper Security Vulnerabilities
WP Wrapper Code Analysis
Output Escaping
Data Flow Analysis
WP Wrapper Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP Wrapper Maintenance & Trust
Maintenance Signals
Community Trust
WP Wrapper Alternatives
Include Me
include-me
Include Me helps to include any external file (textual, HTML or PHP) in posts or pages.
Embed Iframe
embed-iframe
Allows the insertion of code to display an external webpage within an iframe.
PageView
pageview
Insert an iframe and display an external website directly in a post using just a shortcode.
iframe Wrapper
iframe-wrapper
A small little plugin to embed an auto resizing iframe into a WordPress page or post.
Zedna WP Image Lazy Load
wp-image-lazy-load
Image lazy load plugin to boost page load time and save bandwidth by removing all the images, background-images, responsive images, iframes and videos …
WP Wrapper Developer Profile
5 plugins · 1K total installs
How We Detect WP Wrapper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wp-wrapper-iframeid="wp-wrapper-iframe"<iframe class="wp-wrapper-iframe" id="wp-wrapper-iframe" width="