WP Manifestindependent plugin directory
manifest / admin / chirobasix-allow-iframes

CHIROBASIX - Allow iFrames

CHIROBASIX - Allow iFrames - WordPress mu-plugin granting unfiltered_html to admins so podcast embed iframes save correctly via REST API on WP Engine sites.

by ChiroBasix · github.com/chirobasix-llc/chirobasix-allow-iframes

0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/chirobasix-llc/chirobasix-allow-iframes/archive/refs/heads/main.zip

WordPress mu-plugin that grants the unfiltered_html capability to administrators and whitelists trusted iframe hosts (RSS.com, YouTube, Vimeo, Spotify, Apple Podcasts) so podcast embed codes save correctly when written via the WordPress REST API.

WP Engine disables unfiltered_html by default — even for Administrators. This plugin reinstates it for trusted admin users only, with a strict trusted-host check on acf/update_value/name=embed_code as a backstop.

Why this exists

The Copilot publishes podcast episodes by POSTing to /wp-json/wp/v2/podcast with an acf.embed_code value containing an `