# EmbedMe libary

**URL:** https://community.homey.app/t/embedme-libary/148361
**Category:** Questions & Help
**Tags:** app, dashboard, homey-pro
**Created:** [January 2, 2026, 1:14pm UTC](https://community.homey.app/t/embedme-libary/148361 "2026-01-02T13:14:39Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![LRvdLinden](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/lrvdlinden/32/80786_2.png) [@LRvdLinden](https://community.homey.app/u/LRvdLinden)
#### Post date: [January 2, 2026, 1:14pm UTC](https://community.homey.app/t/embedme-libary/148361/1 "2026-01-02T13:14:39Z")

</div>

Hi everyone, first of all, best wishes for 2026!

Many people are currently busy working on Homey dashboards and embedding various iframes. I’ve built a website [https://embedme.nl](https://embedme.nl) with a library where you can test and save embeds.

It might be nice to share useful frames here, so other users can easily reuse them for their own dashboards.

 ![image](https://us1.discourse-cdn.com/flex025/uploads/athom/original/3X/7/1/7192c773d1238243d451f548012da3c40a4481bd.png)

---

<div class="post-metadata">

### Author: ![smarthomesven](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/smarthomesven/32/79712_2.png) [@smarthomesven](https://community.homey.app/u/smarthomesven)
#### Post date: [January 2, 2026, 3:35pm UTC](https://community.homey.app/t/embedme-libary/148361/2 "2026-01-02T15:35:55Z")

</div>

Are the embed codes verified before they get published? I see that you load the iframes in the browser as soon as the page gets opened, is that safe with user-generated content?

---

<div class="post-metadata">

### Author: ![LRvdLinden](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/lrvdlinden/32/80786_2.png) [@LRvdLinden](https://community.homey.app/u/LRvdLinden)
#### Post date: [January 2, 2026, 4:36pm UTC](https://community.homey.app/t/embedme-libary/148361/3 "2026-01-02T16:36:04Z")

</div>

It’s just a copy-and-paste website. What could be unsafe about it? You can create a profile to manage your content or save favorites, or stay anonymous.

---

<div class="post-metadata">

### Author: ![smarthomesven](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/smarthomesven/32/79712_2.png) [@smarthomesven](https://community.homey.app/u/smarthomesven)
#### Post date: [January 2, 2026, 5:08pm UTC](https://community.homey.app/t/embedme-libary/148361/4 "2026-01-02T17:08:50Z")

</div>

It’s because the actual code that users paste in there gets loaded as an iframe. So someone could post an iframe and then it gets loaded for all visitors as soon as the website gets loaded.

So anybody could create a post and then anybody who opens the website also loads that iframe/code.

Also, are you checking if what’s loaded is actually inside of an iframe and not something like a script or `<img src=”x” onerror=”…”>`?

The issue is that you load the code snippets in the browser, because anyone can add code that then gets loaded in the browser of anybody who visits the website.

 ![image](https://us1.discourse-cdn.com/flex025/uploads/athom/original/3X/f/0/f0b8d4d18e6d88fe71c6f247da0c748ee5bbc5a0.png)
