
3D Viewer – 3D Model Viewer – Augmented Reality Security & Risk Analysis
wordpress.org/plugins/ar-vr-3d-model-try-onDisplay 3D models on WordPress & WooCommerce with built-in AR for iOS & Android. Unlimited uploads, no app needed. Gutenberg block included.
Is 3D Viewer – 3D Model Viewer – Augmented Reality Safe to Use in 2026?
Generally Safe
Score 100/1003D Viewer – 3D Model Viewer – Augmented Reality has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ar-vr-3d-model-try-on" plugin v1.9.2 exhibits a generally strong security posture based on the provided static analysis. A significant strength is the complete absence of critical or high-severity taint flows, indicating that user-supplied data is likely being handled and processed safely, with no unsanitized paths identified. Furthermore, the plugin demonstrates good practice by utilizing prepared statements for all SQL queries and a high percentage of proper output escaping, which mitigates common risks like SQL injection and cross-site scripting.
The plugin also appears to be well-defended against common WordPress vulnerabilities, with a clean vulnerability history showing no recorded CVEs. The presence of nonce and capability checks on its entry points, including AJAX handlers and shortcodes, is commendable and contributes to its secure design. However, while the static analysis shows no *unprotected* entry points, the total number of entry points, even if protected, could be a minor concern if not all are rigorously reviewed for potential logic flaws.
In conclusion, this plugin demonstrates a robust approach to security, with a focus on secure coding practices. The lack of identified vulnerabilities and taint flows is highly reassuring. The primary area for vigilance would be to ensure ongoing maintenance and prompt patching of any future issues, though its historical record suggests this may not be a significant concern.
Key Concerns
- Bundled library (Freemius v1.0) may be outdated
3D Viewer – 3D Model Viewer – Augmented Reality Security Vulnerabilities
3D Viewer – 3D Model Viewer – Augmented Reality Release Timeline
3D Viewer – 3D Model Viewer – Augmented Reality Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
3D Viewer – 3D Model Viewer – Augmented Reality Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 40
Maintenance & Trust
3D Viewer – 3D Model Viewer – Augmented Reality Maintenance & Trust
Maintenance Signals
Community Trust
3D Viewer – 3D Model Viewer – Augmented Reality Alternatives
PausAR – 3D and AR for Elementor
pausar-3d-ar-for-elementor
PausAR is a user-friendly and web-based 3D & augmented reality viewer that can be easily integrated into any Elementor powered WordPress website.
AR for WooCommerce
ar-for-woocommerce
Augmented Reality for WooCommerce plugin lets you display 3D models and AR products directly in your store with no app required.
3D Viewer Online
3dvieweronline-wp
An easy, realistic and customizable 3D Viewer to embed 3D models of your products/designs into your Wordpress/WooCommerce website (responsive layout)
AR Model Viewer for WooCommerce
ar-model-viewer-for-woocommerce
The AR Model Viewer for WooCommerce plugin shows 3D models on your website and in augmented reality. Supports .glb and .gltf files.
AR Play
ar-play
Show any 3D Model in augmented reality (AR) trough our Android and iOS app.
3D Viewer – 3D Model Viewer – Augmented Reality Developer Profile
5 plugins · 4K total installs
How We Detect 3D Viewer – 3D Model Viewer – Augmented Reality
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ar-vr-3d-model-try-on/admin/css/style.css/wp-content/plugins/ar-vr-3d-model-try-on/admin/css/editor.css/wp-content/plugins/ar-vr-3d-model-try-on/admin/js/main.js/wp-content/plugins/ar-vr-3d-model-try-on/admin/js/settings.js/wp-content/plugins/ar-vr-3d-model-try-on/admin/js/editor.js/wp-content/plugins/ar-vr-3d-model-try-on/vendor/freemius/assets/css/freemius-base.css/wp-content/plugins/ar-vr-3d-model-try-on/vendor/freemius/assets/js/freemius-base.jsAtlasAiDev/wp-content/plugins/ar-vr-3d-model-try-on/admin/js/main.js/wp-content/plugins/ar-vr-3d-model-try-on/admin/js/settings.js/wp-content/plugins/ar-vr-3d-model-try-on/admin/js/editor.js/wp-content/plugins/ar-vr-3d-model-try-on/vendor/freemius/assets/js/freemius-base.jsar-vr-3d-model-try-on/admin/css/style.css?ver=ar-vr-3d-model-try-on/admin/css/editor.css?ver=ar-vr-3d-model-try-on/admin/js/main.js?ver=ar-vr-3d-model-try-on/admin/js/settings.js?ver=ar-vr-3d-model-try-on/admin/js/editor.js?ver=HTML / DOM Fingerprints
ar-vr-3d-model-try-on-settings-wrapar-vr-3d-model-try-on-editor-wrapar-vr-3d-model-try-on-viewer-containeratlas-ar-frontend-button<!-- The main plugin class that returns all the PHP needed --><!-- Main Class for the plugin --><!-- HPOS compatibility --><!-- Initialize Compression feature (v1.8.0+) -->+6 moredata-ar-vr-3d-model-try-on-iddata-model-srcdata-ar-enableddata-ar-button-textar_vr_3d_model_try_on_ajax_objectar_try_on_settings_paramsar_try_on_editor_paramsAV3MTOav3mto_fs/wp-json/ar-vr-3d-model-try-on/v1/models/wp-json/ar-vr-3d-model-try-on/v1/settings/wp-json/ar-vr-3d-model-try-on/v1/compression/upload/wp-json/ar-vr-3d-model-try-on/v1/compression/delete[ar_vr_3d_model_try_on id='1']