Webflow tightens Marketplace review after malicious embed apps found injecting scripts
A wave of third-party Webflow Marketplace apps were found injecting obfuscated scripts via legitimate-looking embeds. Here's what happened and what to check on your own site.
Multiple Webflow Marketplace apps · Obfuscated third-party scripts · Audit installed embeds and review your CSP.
Over the past few weeks, security researchers and Webflow's own trust and safety team identified a cluster of third-party Marketplace apps — mostly in the chat widget, personalisation and A/B-testing categories — that were injecting obfuscated scripts beyond what their listed permissions described. Webflow has since tightened its App Marketplace review process for anything that touches the DOM.
What happened
Several apps published to the Marketplace under legitimate-looking listings were found, after installation, to load additional third-party scripts not disclosed at install time — in some cases scripts capable of capturing form input or injecting further embeds dynamically. Webflow removed the affected apps and published a review-process update requiring stricter static analysis of any app requesting DOM or script-injection permissions.
Who this affects
- Sites with chat widget, personalisation or A/B-testing apps installed from the Marketplace before this review update
- Sites with custom code embeds copied from third-party snippets rather than the Marketplace directly
- Agencies managing multiple client Webflow sites, where the same app may be installed across a fleet
What you should do
- Review every installed Marketplace app and custom embed — remove anything you don't actively use
- Check browser network activity on a staging copy of your site for unexpected third-party script origins
- Add or tighten a Content Security Policy to restrict which script origins your site will execute
- If you manage a fleet, audit all sites rather than assuming the issue is isolated to one
How we handled this for managed clients
We ran an embed audit across every managed Webflow client as soon as the affected app list was published, cross-referencing installed apps and custom embeds against the disclosed list. No managed client was running an affected app, but two had unrelated legacy embeds removed as a precaution. No action is needed if you're on a WebsiteSupport.io Webflow retainer.
We can run a one-off embed and script audit and tell you plainly what's there, what it does, and what it's safe to remove.
Talk to us about Webflow support →Related articles
Umbraco backoffice authentication bypass — what managed clients need to know
A critical flaw (CVE-2026-41205) in the Umbraco backoffice authentication flow could allow session hijacking. Managed clients were patched immediately.
24 Jul 2026 · 4 min readPlatform updatesWebflow leans further into AI — what agencies and marketing teams should know
Webflow's latest release pushes AI-assisted design and content tooling further. Here's what changes for teams who rely on custom code and integrations.
19 Jul 2026 · 5 min readSecurityCritical access-bypass patched in Drupal core
A significant vulnerability (SA-CORE-2026-008) affecting Drupal 10.3–11.1. Managed clients were patched within the SLA window.
30 May 2026 · 3 min readStay ahead of the next release
Security alerts, platform updates and industry analysis — straight to your inbox.