WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: ruigehond-embed (Used by 11 domains)

Ruigehond embed

👤 Joeri van Veen 📦 v1.4.2 🔗 Plugin Homepage

Plugin to embed selected urls from your site elsewhere.

Security

Other embedding will be prohibited by default, with an X-Frame-Options header and, optionally, a Content Security Policy header.
This will secure your WordPress website from a number of fairly easy attacks.

To make this plugin especially useful you can now allow (third party) websites to embed specific urls from your site.
Easily reuse forms or other content from your main site on satellite sites you own, without opening up any of them to attack.

Quick setup

Activate the plugin and go to Settings -> Ruigehond embed.
Add a reference (e.g. general-contact-form) in the title field and save the settings.
Add a slug it should serve (e.g. /contact-clean/) in the embed field.
Add urls that may embed this, aka referrers, (e.g. https://my-satellite.site) in the textarea.

Embedding

Install the plugin on your satellite site. This has the added benefit of locking down that site as well.

Use the simple shortcode on that site to generate an iframe with the embedded content:
[ruigehond-embed src="https://my-main.site/ruigehond_embed/general-contact-form"]

Watch the form magically and safely be embedded. Other sites will continue to not be able to embed your content.

You can also embed using a regular iframe in html, as long as the referrer is whitelisted.
However, by using the plugin and shortcode, the height of the iframe will automatically be adjusted to fit the content.

Use htaccess

This plugin adds lines (clearly marked) at the beginning of your htaccess file.
They need not be at the beginning, but they need to be before the WordPress lines, or any other lines that corrupt the THE_REQUEST var.

This plugin needs mod_headers, mod_rewrite and mod_setenvif to be activated, but they probably already are.

Without htaccess

When the htaccess is not processed, the plugin itself works directly with the request in the php processor.
The CSP header is not supported in that case.
Also, other plugins (especially caching plugins) may already have decided on a different route and this plugin might not work.

Content Security Policy

You can switch on the Content Security Policy (or CSP) header in this plugin, which is the most modern way to tackle these issues.
However, other plugins may interfere, so be sure to check whether the CSP header is to your liking in practice.

This plugin will add a CSP header if none is present yet.
But if one is present, the frame-ancestors directive must be present in it for this plugin to work.
It will only set the frame-ancestors directive, none of the others (to not break your site).

DomainExposuresHeadersLast Checked
j*e*i*a*v*e*.eu (WP 6.9.4) F 2026-05-24 14:17:24
g*a*f*t*n*t*e*k.nl C 2026-05-08 18:04:07
w*-*e*e*o*e*.eu (WP 6.9.4) F 2026-05-04 12:57:55
g*a*f*t*n*t*o*k.it C 2026-05-02 08:03:06
g*a*f*t*n*t*o*k.es C 2026-05-02 08:03:06
g*a*f*t*n*t*o*k.se C 2026-05-02 08:03:06
g*a*f*t*n*t*o*k.dk C 2026-05-02 08:03:06
g*a*f*t*n*t*o*k.fr C 2026-05-02 08:03:06
g*a*f*t*n*t*o*k.de C 2026-05-02 08:03:06
g*a*f*t*n*t*o*k.com C 2026-04-25 16:27:51
g*a*f*t*n*t*e*k.com C 2026-04-25 16:27:51

Top 50 Plugins

Plugin Count
elementor 1,755,610
contact-form-7 1,723,923
elementor-pro 1,023,690
woocommerce 800,320
revslider 606,992
jetpack 459,151
js_composer 423,885
wp-rocket 325,346
essential-addons-for-elementor-lite 282,228
gravityforms 258,476
complianz-gdpr 245,931
cookie-law-info 223,585
instagram-feed 222,997
sitepress-multilingual-cms 215,848
google-site-kit 215,366
google-analytics-for-wordpress 210,876
header-footer-elementor 206,411
elementskit-lite 198,363
bluehost-wordpress-plugin 189,368
gutenberg 157,980
gutenberg-core 145,780
cookie-notice 145,177
wpforms-lite 128,976
the-events-calendar 128,273
litespeed-cache 125,607
gtranslate 123,989
astra-sites 119,643
popup-maker 114,247
woocommerce-payments 111,513
tablepress 103,779
honeypot 95,034
coblocks 94,460
astra-addon 93,153
all-in-one-seo-pack 92,155
wp-smushit 91,736
duracelltomi-google-tag-manager 90,780
LayerSlider 90,170
bb-plugin 89,615
premium-addons-for-elementor 85,042
akismet 84,687
megamenu 83,401
cleantalk-spam-protect 82,844
mailchimp-for-wp 82,478
woocommerce-gateway-stripe 81,419
fusion-builder 78,143
ml-slider 77,307
formidable 77,108
ewww-image-optimizer 76,399
borlabs-cookie 75,737
wp-pagenavi 75,411

Top 50 Themes

Theme Count
hello-elementor 600,055
Divi 502,503
astra 416,692
flatsome 124,553
Avada 122,014
generatepress 114,704
pub 100,812
oceanwp 81,491
kadence 76,068
enfold 70,277
salient 65,803
twentyseventeen 54,778
bb-theme 54,505
twentytwentyfour 53,379
h4 51,585
cocoon-master 50,873
betheme 50,616
blocksy 49,076
dt-the7 44,908
twentytwentyfive 42,750
neve 38,247
Avada-Child-Theme 36,878
gox 32,823
bridge 32,465
twentytwentyone 32,011
woodmart 31,958
lightning 30,061
twentytwenty 29,525
swell 27,507
Impreza 25,654
bricks 25,234
twentytwentythree 24,044
Newspaper 22,636
twentytwentytwo 19,941
epik-redesign 19,305
uncode 18,631
sydney 18,495
twentysixteen 17,815
pro 17,706
storefront 17,513
voxel 17,020
extendable 15,234
kubio 14,535
Total 14,382
yith-wonder 14,005
hello-theme-child-master 12,916
themify-ultra 12,801
factory-templates-4 12,574
yootheme 12,561
hestia 12,454