
Code Three 3D Interactive Security & Risk Analysis
wordpress.org/plugins/code-three-3d-interactiveEasily build animated/interactive 3D scenes and embed using a shortcode. Take your site to the next dimension. Powered by Three.js
Is Code Three 3D Interactive Safe to Use in 2026?
Generally Safe
Score 100/100Code Three 3D Interactive has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "code-three-3d-interactive" plugin version 1.0 exhibits a generally good security posture based on the provided static analysis. The absence of known vulnerabilities and CVEs, combined with the use of prepared statements for all SQL queries and a high percentage of properly escaped output, indicates that the developers have followed many best practices.
However, there are a few areas that warrant attention. The taint analysis revealed two flows with unsanitized paths, which, while not classified as critical or high severity in this instance, represent potential avenues for injection attacks if the data is not properly handled further down the line. The presence of an external HTTP request, though not inherently a vulnerability, can be a vector for certain types of attacks if not implemented with strict validation and sanitization of the requested data. Furthermore, while the plugin has entry points, they are all protected by authentication or capability checks, which is a significant strength.
Overall, this plugin appears to be developed with security in mind, particularly regarding database interactions and output handling. The lack of historical vulnerabilities further reinforces this. The primary concern lies in the identified unsanitized paths in the taint analysis, which should be investigated for potential indirect risks or future exploitable conditions. Despite this, the current state suggests a relatively low risk profile, with most potential attack vectors being adequately mitigated.
Key Concerns
- Taint flows with unsanitized paths
- External HTTP request detected
Code Three 3D Interactive Security Vulnerabilities
Code Three 3D Interactive Code Analysis
Output Escaping
Data Flow Analysis
Code Three 3D Interactive Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
Code Three 3D Interactive Maintenance & Trust
Maintenance Signals
Community Trust
Code Three 3D Interactive Alternatives
ThreeWP
threewp
Easily integrate Three.js with WordPress to create and display 3D models and animations.
AKDev Spline animation – Delight your users experience with 3d scroll animations.
akdev-spline-animation
Create Spline 3d scrolling animations with ease and wow your users.
Cube 3D Slider
cube-3d-slider
Display cube 3D slider in your website.
XPAC Lottie Interactive Animations
xpac-lottie-interactive-animation
A powerful tool to add impressive light-weight animations to your website with a Wordpress native site editor, optimized for performance and Full Site …
Cube 3D
cube-3d
Display cube 3D in your website.
Code Three 3D Interactive Developer Profile
1 plugin · 10 total installs
How We Detect Code Three 3D Interactive
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/code-three-3d-interactive/assets/css/styles.css/wp-content/plugins/code-three-3d-interactive/assets/js/scene.js/wp-content/plugins/code-three-3d-interactive/assets/js/local.js/wp-content/plugins/code-three-3d-interactive/assets/js/admin.js/wp-content/plugins/code-three-3d-interactive/assets/js/local.js/wp-content/plugins/code-three-3d-interactive/assets/js/scene.js/wp-content/plugins/code-three-3d-interactive/assets/js/admin.jsHTML / DOM Fingerprints
c33d_sceneloadScreenloadCircleloadInnerCircledata-scene-iddata-scene-datadata-plugin-urldata-is-adminc33dlocaliseddatac33dadminlocaliseddata[c33d_scene