
Byrst 3D for WooCommerce Security & Risk Analysis
wordpress.org/plugins/byrst-3d-for-woocommerceByrst 3D for WooCommerce: Create and Display 3D Models of Your Products in 3D & AR
Is Byrst 3D for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100Byrst 3D for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "byrst-3d-for-woocommerce" plugin version 1.0.1 exhibits a concerning security posture due to a significant number of unprotected AJAX handlers, representing its entire attack surface. While the plugin demonstrates good practices in utilizing prepared statements for SQL queries and a high rate of output escaping, the lack of authentication checks on 14 AJAX entry points is a critical weakness. This means any unauthenticated user could potentially trigger these functionalities, leading to unintended consequences or even exploit vulnerabilities if other weaknesses exist.
The static analysis did not reveal any direct indicators of dangerous functions or file operations. However, the taint analysis found three flows with unsanitized paths, which, while not classified as critical or high severity in this report, warrant careful investigation. The absence of any recorded vulnerabilities in the plugin's history is a positive sign, suggesting either diligent security development or a lack of targeted attacks. Nonetheless, the presence of unsanitized paths combined with unprotected AJAX handlers creates a potential avenue for exploitation.
In conclusion, while the plugin demonstrates strengths in its handling of SQL queries and output escaping, the prevalent lack of authentication on its AJAX endpoints is a major security concern. The taint analysis findings, although not severe in classification here, further highlight areas that require developer attention. The plugin's clean vulnerability history is encouraging but does not negate the immediate risks posed by the exposed AJAX functionality.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths
Byrst 3D for WooCommerce Security Vulnerabilities
Byrst 3D for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Byrst 3D for WooCommerce Attack Surface
AJAX Handlers 14
WordPress Hooks 18
Maintenance & Trust
Byrst 3D for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Byrst 3D for WooCommerce Alternatives
AR for WooCommerce
ar-for-woocommerce
Augmented Reality for WooCommerce plugin lets you display 3D models and AR products directly in your store with no app required.
TouchTry Eye Fit
touchtry-eye-fit
Bring immersive Augmented Reality (AR) try-on experiences for eyewear products directly to your WooCommerce store.
AR/3D Product Viewer & Try-On
aryel-ar-3d-product-viewer-try-on
Connect your online store to Aryel and allow your customers to access realistic and true-to-size product previews and virtual try-ons in just 1 click.
AR for WordPress
ar-for-wordpress
Augmented Reality for WordPress lets you showcase 3D models in an interactive viewer and AR on iOS and Android, with no app downloads needed.
3D Product configurator for WooCommerce
expivi
Easy-to-use 3D product configurator to show your products in 360°
Byrst 3D for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect Byrst 3D for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/byrst-3d-for-woocommerce/includes/css/byrst-woocommerce-plugin-admin-settings.css/wp-content/plugins/byrst-3d-for-woocommerce/includes/css/byrst-woocommerce-plugin-admin-product.css/wp-content/plugins/byrst-3d-for-woocommerce/includes/js/byrst-woocommerce-plugin-admin-settings-dist.js/wp-content/plugins/byrst-3d-for-woocommerce/includes/js/byrst-woocommerce-plugin-admin-settings-dist.jsbyrst-woocommerce-plugin-admin-settings.css?ver=byrst-woocommerce-plugin-admin-product.css?ver=byrst-woocommerce-plugin-admin-settings-dist.js?ver=HTML / DOM Fingerprints
ajax_object_settings