Eye for Craft CMS

Free for Craft CMS 5

Iframes that behave

An iframe in a CMS goes wrong four ways: it's the wrong size, it loads before anyone scrolls to it, it hands your reader to a third party before they asked, and sometimes the other site refuses to be framed and only tells the browser console. Eye deals with all four.

Eye

Build it once, use it anywhere

An embed is a library element with a handle. Craft already parses reference tags in every rich-text value, so the same tag works in CKEditor, Redactor and plain HTML fields with no template changes. The editor buttons only write the tag for you.

twig
{# In any rich-text field #}
{eye:promo-video:render}
{eye:promo-video:render(click,height=600)}

{# In a template #}
{{ craft.eye.render('promo-video') }}
{{ craft.eye.url('https://youtu.be/dQw4w9WgXcQ') }}
{{ entry.video|eye({ align: 'full' }) }}

Features

Each one fixes a specific way iframes go wrong.

27 providers, already configured

Paste a YouTube, Vimeo, Loom, Spotify, Google Maps, Figma, Calendly or Typeform link and Eye writes the real embed URL with the right aspect ratio and allow tokens, and uses the provider's cookie-free host where there is one.

  • Anything else is framed as-is
  • Ten pastes of the same URL make one library entry

The right size, every time

Five modes: a responsive aspect-ratio box, a fixed height, auto height that the frame reports itself, proxy, and inline. A 1 KB child script handles auto height across origins when you own both pages.

Consent that actually waits

Click-to-load keeps the iframe inside a <template> element, so nothing is requested until the reader asks. A hidden iframe still loads, which is the mistake most consent banners make.

  • Provider name and poster on the card
  • The reader's choice can be remembered for each host

Know before you publish

A page that refuses to be framed leaves a blank rectangle and gives the browser no signal. Eye reads X-Frame-Options and frame-ancestors when you save and explains the result in plain language, on the URL that actually goes in the frame.

  • A status column on the embed index
  • eye/embeds/check --failOnProblem for CI

A proxy that isn't an open proxy

Proxy mode fetches a page on the server and serves it from your own domain, which gets past X-Frame-Options and makes CSS injection and content extraction reliable. It's off by default and needs an explicit host allowlist.

  • Every resolved address must be public, and the connection is pinned to it
  • The public route never accepts a URL, only a uid or a signed payload

Every third-party frame in one place

A pasted URL becomes a library element, so every embed on the site ends up in one index. You can audit them, switch one off, or move it behind a consent card.

Eye in the control panel

Real screens from a Craft 5 install: the embed library with its framing column, an embed that refuses to be framed, and a click-to-load card on the front end.

The Eye embeds index in the Craft control panel, listing eleven embeds with their provider, mode, framing status and reference tag
An Eye embed edit screen showing a red Refuses framing status and the explanation that the page sets frame-ancestors 'none'
A click-to-load card over a video poster asking whether to load content from YouTube, with a Load content button

Screenshots from a live install, not mockups.

Frequently Asked Questions

Worth knowing before you install it.

Embeds that work

Free for Craft CMS 5, with no editions and no licence key.