
3DPrint Lite Security & Risk Analysis
wordpress.org/plugins/3dprint-liteA plugin for selling 3D printing services.
Is 3DPrint Lite Safe to Use in 2026?
Generally Safe
Score 91/1003DPrint Lite has a strong security track record. Known vulnerabilities have been patched promptly.
The 3dprint-lite v2.1.3.9 plugin exhibits a mixed security posture. While it demonstrates good practices in output escaping (95%) and nonce checks (29), and has no known unpatched CVEs, significant concerns exist regarding its attack surface and past vulnerability history. The presence of two unprotected AJAX handlers presents a direct entry point for unauthenticated attackers, which is a substantial risk given the total of three entry points. Furthermore, 2 out of 19 analyzed taint flows had unsanitized paths, although these were not classified as critical or high severity. This suggests a potential for vulnerabilities that might not be immediately obvious through static analysis alone.
The plugin's vulnerability history is particularly alarming, with a total of 7 known CVEs, including one previously critical vulnerability. The common types of vulnerabilities (SQL Injection, CSRF, Unrestricted Upload) indicate recurring weaknesses in how the plugin handles user input and performs sensitive operations. While the most recent vulnerability was in 2025, this past record suggests a pattern of security flaws that require diligent monitoring and prompt patching. The plugin does utilize prepared statements for a majority of its SQL queries (61%), which is a positive sign, but the remaining percentage, coupled with the history of SQL injection, warrants caution.
In conclusion, while the plugin has made strides in secure coding practices, the unprotected AJAX handlers and the historical prevalence of severe vulnerabilities are significant weaknesses. The potential for further issues, as hinted by the unsanitized taint flows, requires a high level of vigilance. It is recommended to prioritize patching any new vulnerabilities immediately and to thoroughly review and secure the unprotected AJAX endpoints.
Key Concerns
- 2 unprotected AJAX handlers
- 2 flows with unsanitized paths
- 7 total known CVEs (incl. 1 critical)
- Common vuln types: SQLi, CSRF, Unrestricted Upload
3DPrint Lite Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
3DPrint Lite <=2.1.3.6 - Authenticated (Admin+) SQL Injection via 'infill_text'
3DPrint Lite <=2.1.3.6 - Authenticated (Admin+) SQL Injection via 'material_text'
3DPrint Lite <=2.1.3.6 - Authenticated (Admin+) SQL Injection via 'printer_text'
3DPrint Lite <=2.1.3.6 - Authenticated (Admin+) SQL Injection via 'coating_text'
3DPrint Lite <= 2.1.3.5 - Cross-Site Request Forgery
3DPrint Lite <= 2.0.9.9 - Cross-Site Request Forgery to Settings Update
3DPrint Lite < 1.9.1.5 - Arbitrary File Upload
3DPrint Lite Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
3DPrint Lite Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 16
Scheduled Events 1
Maintenance & Trust
3DPrint Lite Maintenance & Trust
Maintenance Signals
Community Trust
3DPrint Lite Alternatives
Shop3D – 3D Print on Demand
shop-3d
Instant on-demand manufacturing plugin - from 3D file into physical product
3DHubs
3dhubs
Displays a 3DHubs button in the sidebar or directly in a text field.
STL Viewer
stl-viewer
With a simple shortcode you can enable and embed a WebGL viewer to show 3d stl files.
3D Printing Pro by Boostfab
3d-printing-pro-by-boostfab
Allow your users to get a quote for 3D printing and laser cutting jobs.
Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer
3d-flipbook-dflip-lite
Dear Flipbook creates PDF Flipbook, 3D Flipbook, PDF viewer, PDF embed for WordPress sites. Create impressive and realistic 3D flipbooks with PDFs.
3DPrint Lite Developer Profile
2 plugins · 2K total installs
How We Detect 3DPrint Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/3dprint-lite/js/3dprint-lite.js/wp-content/plugins/3dprint-lite/css/3dprint-lite.css/wp-content/plugins/3dprint-lite/js/plupload/plupload.full.min.js/wp-content/plugins/3dprint-lite/js/plupload/jquery.plupload.queue.js/wp-content/plugins/3dprint-lite/js/plupload/plupload.html5.js/wp-content/plugins/3dprint-lite/js/plupload/plupload.flash.js/wp-content/plugins/3dprint-lite/js/plupload/plupload.silverlight.js/wp-content/plugins/3dprint-lite/js/plupload/plupload.html4.js+3 more/wp-content/plugins/3dprint-lite/js/3dprint-lite.js/wp-content/plugins/3dprint-lite/js/plupload/plupload.full.min.js/wp-content/plugins/3dprint-lite/js/plupload/jquery.plupload.queue.js/wp-content/plugins/3dprint-lite/js/plupload/plupload.html5.js/wp-content/plugins/3dprint-lite/js/plupload/plupload.flash.js/wp-content/plugins/3dprint-lite/js/plupload/plupload.silverlight.js+3 morever=2.1.3.9HTML / DOM Fingerprints
p3dlite-main-wrapperp3dlite-upload-formp3dlite-printers-listp3dlite-materials-listp3dlite-order-formp3dlite-cartp3dlite-checkout<!-- 3dprint-lite plugin --><!-- End 3dprint-lite plugin --><!-- End of 3DPrint Lite Plugin -->data-plugin-name="3dprint-lite"data-plugin-version="2.1.3.9"window.p3d_lite_paramswindow.p3dlite_upload_paramswindow.p3dlite_l10n[p3dlite_upload_form][p3dlite_printer_list][p3dlite_material_list][p3dlite_order_form]