
AR Play Security & Risk Analysis
wordpress.org/plugins/ar-playShow any 3D Model in augmented reality (AR) trough our Android and iOS app.
Is AR Play Safe to Use in 2026?
Generally Safe
Score 85/100AR Play has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ar-play" plugin v1.0.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by using prepared statements for all SQL queries and avoiding file operations and external HTTP requests. Its vulnerability history is clean, with no recorded CVEs, which suggests a generally secure development process or limited exposure to sophisticated attacks. However, there are significant areas for concern in the static analysis. The low percentage of properly escaped output (20%) is a major red flag, indicating a high likelihood of cross-site scripting (XSS) vulnerabilities. The taint analysis revealing a flow with unsanitized paths, even without a critical or high severity classification, points to potential information leakage or execution manipulation if this path can be triggered by user input. The absence of nonce checks and capability checks, especially given the presence of a shortcode as an entry point, means that actions triggered by the shortcode might not be properly authorized or protected against CSRF attacks. While the attack surface is currently small and has no direct unauthenticated entry points identified in this analysis, the combination of weak output escaping and potential unsanitized flows presents a notable risk.
Key Concerns
- Low output escaping percentage (20%)
- Taint flow with unsanitized path
- Missing nonce checks
- Missing capability checks
AR Play Security Vulnerabilities
AR Play Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
AR Play Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
AR Play Maintenance & Trust
Maintenance Signals
Community Trust
AR Play Alternatives
Augmented Reality Viewer – 3D Model Viewer
ar-viewer
By using this plugin, you can easily create an augmented reality viewer or 3D model viewer anywhere on your website.
AR for WordPress
ar-for-wordpress
Augmented Reality for WordPress lets you showcase 3D models in an interactive viewer and AR on iOS and Android, with no app downloads needed.
ArtPlacer Widget
artplacer-widget
Allow your visitors visualize how artworks look on walls as soon as they land on your website!
3D Product configurator for WooCommerce
expivi
Easy-to-use 3D product configurator to show your products in 360°
SwiftXR (3D/AR/VR) Viewer
swiftxr-3darvr-viewer
Easily enhance customer engagement with immersive 3D, AR, and VR experiences
AR Play Developer Profile
2 plugins · 20 total installs
How We Detect AR Play
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ar-play/assets/css/arplaystyle.css/wp-content/plugins/ar-play/assets/js/arplayscript.js/wp-content/plugins/ar-play/assets/js/arplayscript.jsHTML / DOM Fingerprints
arplay-qr-wraparplay-qrarplay-btndata-arplay-url<div class="arplay-qr-wrap arplay-qr"<img src="https://arplay.app/api/generate-qr?<a href="https://arplay.app/class="arplay-btn"