
3D Viewer – glb/gltf Viewer by WPSE Security & Risk Analysis
wordpress.org/plugins/advanced-3d-model-viewerEmbed and interact with 3D models in your WordPress content using a block, shortcode, or custom post type.
Is 3D Viewer – glb/gltf Viewer by WPSE Safe to Use in 2026?
Generally Safe
Score 100/1003D Viewer – glb/gltf Viewer by WPSE has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "advanced-3d-model-viewer" plugin version 1.0.0 demonstrates a strong security posture based on the provided static analysis. The absence of dangerous functions, the consistent use of prepared statements for SQL queries, and the proper escaping of all output are significant strengths. Furthermore, the lack of file operations and external HTTP requests reduces the potential for common attack vectors. The plugin also exhibits no known vulnerabilities in its history, suggesting a diligent approach to security by its developers.
However, the analysis does reveal a critical area for concern: the complete absence of nonce and capability checks across all entry points. While the current attack surface appears small (one shortcode with no apparent auth checks), this lack of security fundamentals means that any future expansion of functionality or unforeseen vulnerabilities could be easily exploited. The zero taint flows are positive, but this should not overshadow the fundamental security gaps.
In conclusion, the plugin has excellent technical implementations for sanitization and query security. Nevertheless, the complete disregard for authentication and authorization mechanisms represents a significant weakness. The developers should prioritize implementing nonce and capability checks to ensure that even benign functionalities cannot be abused by unauthenticated users.
Key Concerns
- Missing nonce checks
- Missing capability checks
3D Viewer – glb/gltf Viewer by WPSE Security Vulnerabilities
3D Viewer – glb/gltf Viewer by WPSE Code Analysis
Output Escaping
3D Viewer – glb/gltf Viewer by WPSE Attack Surface
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
3D Viewer – glb/gltf Viewer by WPSE Maintenance & Trust
Maintenance Signals
Community Trust
3D Viewer – glb/gltf Viewer by WPSE Alternatives
3D Viewer Online
3dvieweronline-wp
An easy, realistic and customizable 3D Viewer to embed 3D models of your products/designs into your Wordpress/WooCommerce website (responsive layout)
ExploreXR
explorexr
Interactive 3D models for WordPress. Upload GLB/GLTF files, embed via shortcode, and extend with modular add-ons. No coding required.
3D Webviewer by Arty
3d-webviewer-by-arty
3D model web viewer by Arty.
Press3D
press3d
Display interactive 3D models (STL, OBJ, GLB, GLTF) with Gutenberg blocks and shortcodes.
3D Product Viewer & WebAR for WooCommerce
wc-product-3d-viewer
The Viraview plugin allows your Woocommerce powered webshop to display your products in 3D & WebAR for PC, Android and Apple.
3D Viewer – glb/gltf Viewer by WPSE Developer Profile
3 plugins · 90 total installs
How We Detect 3D Viewer – glb/gltf Viewer by WPSE
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-3d-model-viewer/assets/css/main.css/wp-content/plugins/advanced-3d-model-viewer/assets/js/frontend.js/wp-content/plugins/advanced-3d-model-viewer/assets/js/editor.js/wp-content/plugins/advanced-3d-model-viewer/build/index.js/wp-content/plugins/advanced-3d-model-viewer/assets/js/frontend.js/wp-content/plugins/advanced-3d-model-viewer/assets/js/editor.js/wp-content/plugins/advanced-3d-model-viewer/build/index.jsadvanced-3d-model-viewer/assets/css/main.css?ver=advanced-3d-model-viewer/assets/js/frontend.js?ver=advanced-3d-model-viewer/assets/js/editor.js?ver=advanced-3d-model-viewer/build/index.js?ver=HTML / DOM Fingerprints
a3dmv-model-viewerdata-a3dmv-model-urlwp[a3dmv_model_viewer