CHIROBASIX - Allow iFrames
CHIROBASIX - Allow iFrames - WordPress mu-plugin granting unfiltered_html to admins so podcast embed iframes save correctly via REST API on WP Engine sites.
by ChiroBasix · github.com/chirobasix-llc/chirobasix-allow-iframes
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/chirobasix-llc/chirobasix-allow-iframes/archive/refs/heads/main.zipWordPress mu-plugin that grants the unfiltered_html capability to administrators and whitelists trusted iframe hosts (RSS.com, YouTube, Vimeo, Spotify, Apple Podcasts) so podcast embed codes save correctly when written via the WordPress REST API.
WP Engine disables unfiltered_html by default — even for Administrators. This plugin reinstates it for trusted admin users only, with a strict trusted-host check on acf/update_value/name=embed_code as a backstop.
Why this exists
The Copilot publishes podcast episodes by POSTing to /wp-json/wp/v2/podcast with an acf.embed_code value containing an `