Embeds are back, for the hosts you choose
Version 1.1.0 started sanitising the widget's HTML, and that stripped every <iframe> along with it. It closed a real hole, but it also took away the main reason people reach for an HTML widget: a YouTube video, a map, an embedded form. This release brings embeds back, from the places you name and nowhere else.
There is a new Allowed iframe hosts box on the extension's settings page. Put one host on each line:
www.youtube.com
*.vimeo.com
An embed is kept only if it loads from a host on that list. A plain entry matches that host exactly. A *. prefix matches any subdomain, so *.vimeo.com covers player.vimeo.com but not vimeo.com by itself, and you can list both if you need both.
The box starts empty, and an empty box strips every iframe exactly as it does today. Nothing changes on your forum until you decide to allow something.
Three things the setting deliberately cannot switch off. Only http and https embeds are ever kept. Script tags, event-handler attributes and javascript: links are still removed as before. And an iframe carrying its own HTML instead of a web address is always dropped, because there would be no address to check against your list.
One thing worth knowing: the checking happens in your visitors' browsers. Treat the allowlist as a guard against pasting something you did not mean to, rather than as a security boundary. Anyone who can edit this setting is already an administrator of your forum.
After updating
Run php flarum cache:clear, so the rebuilt assets are the ones your visitors get.