Skip to content

Security

  • Anyone who can save a snippet can run JavaScript on every public page of your site, in your visitors’ browsers, on your origin.
  • Only users with the plugins:manage permission (Admins) can create, edit, enable or delete snippets. Treat that permission accordingly.
  • Editors (plugins:read) can see the snippet list, but the API never sends them snippet code.
  • Nothing is ever output on /_emdash/ admin paths, so a broken snippet can’t lock you out of the admin.
  • Keep the number of Admins small.
  • Prefer providers’ official snippets, loaded from their own domains.
  • Use the change log to review who changed what.
  • If something goes wrong, use the kill switch first and investigate after. Remember to purge any edge HTML cache.
  • If you use a Content Security Policy, allow the domains your snippets load from.

The plugin requests only hooks.page-fragments:register. Native plugins have no consent prompt on upgrade, so adding a capability is always a major version. See Versioning.

Please don’t post vulnerability details in a public issue. Open an issue asking for a private contact, and the maintainer will follow up.