
Augmented Reality Viewer – 3D Model Viewer Security & Risk Analysis
wordpress.org/plugins/ar-viewerBy using this plugin, you can easily create an augmented reality viewer or 3D model viewer anywhere on your website.
Is Augmented Reality Viewer – 3D Model Viewer Safe to Use in 2026?
Generally Safe
Score 100/100Augmented Reality Viewer – 3D Model Viewer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ar-viewer v1.1.3 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, exclusively using prepared statements for SQL, and 100% proper output escaping are excellent practices. The plugin also has no recorded vulnerabilities or CVEs, suggesting a history of secure development. However, a significant concern is the complete lack of nonce checks and capability checks across all entry points, including the single shortcode. While the attack surface is currently small and there are no immediate indications of exploitable taint flows, this absence of authorization controls represents a critical weakness. An attacker could potentially exploit this to trigger unintended plugin actions if the shortcode's functionality is not inherently benign or if user interaction is not strictly required to invoke it. In conclusion, while the code demonstrates good internal security measures, the lack of authorization checks leaves it vulnerable to potential privilege escalation or unauthorized action, especially as the plugin grows or its functionality becomes more complex.
Key Concerns
- Missing nonce checks
- Missing capability checks
Augmented Reality Viewer – 3D Model Viewer Security Vulnerabilities
Augmented Reality Viewer – 3D Model Viewer Code Analysis
Output Escaping
Augmented Reality Viewer – 3D Model Viewer Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Augmented Reality Viewer – 3D Model Viewer Maintenance & Trust
Maintenance Signals
Community Trust
Augmented Reality Viewer – 3D Model Viewer Alternatives
AR for WordPress
ar-for-wordpress
Augmented Reality for WordPress lets you showcase 3D models in an interactive viewer and AR on iOS and Android, with no app downloads needed.
SwiftXR (3D/AR/VR) Viewer
swiftxr-3darvr-viewer
Easily enhance customer engagement with immersive 3D, AR, and VR experiences
3D Viewer – Display Interactive 3D Models
3d-viewer
3D Viewer lets you embed interactive 3D models and 360 product views on WordPress sites with support for GLB, GLTF, OBJ, STL, FBX, DAE, and BIM.
Emb3D Model Viewer
emb3d-model-viewer
A 3D model viewer for Elementor and WooCommerce
Kento 3D Model Viewer
kento-3d-model-viewer
Display 3D model on wordPress page, post, or custom page, 3D model rotate, zooming enabled.
Augmented Reality Viewer – 3D Model Viewer Developer Profile
24 plugins · 251K total installs
How We Detect Augmented Reality Viewer – 3D Model Viewer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ar-viewer/build/blocks/ar-viewer/wp-content/plugins/ar-viewer/assets/app/vendor/model-viewer.min.jsar-viewer/style.css?ver=ar-viewer/app/vendor/model-viewer.min.js?ver=HTML / DOM Fingerprints
ar-viewerdata-srcdata-posterdata-environment-imagedata-altdata-widthdata-height+3 moremodelViewer<model-viewer width= height= src= ar environment-image=