
D3 Data Fields Security & Risk Analysis
wordpress.org/plugins/d3-data-fieldsCreate WordPress data fields and allows data access by shortcodes.
Is D3 Data Fields Safe to Use in 2026?
Generally Safe
Score 85/100D3 Data Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "d3-data-fields" v0.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the proper escaping of all output signals robust development practices. Furthermore, the lack of file operations and external HTTP requests minimizes potential attack vectors. The presence of a capability check, albeit only one, is a positive sign for access control.
However, the analysis reveals a notable concern: the complete absence of nonce checks across all entry points, particularly the 53 shortcodes. While there are no critical taint flows or unpatched vulnerabilities historically, this omission creates a significant risk for Cross-Site Request Forgery (CSRF) attacks. Attackers could potentially trick authenticated users into executing unintended actions via these shortcodes if they lack sufficient user input validation or capability checks beyond the single observed instance.
The vulnerability history being clear of any recorded CVEs is highly encouraging and suggests a history of secure development or minimal exposure. Nevertheless, the absence of historical issues should not be interpreted as a guarantee of current security, especially given the identified absence of nonce checks. In conclusion, the plugin demonstrates good foundational security but has a critical oversight regarding nonce protection for its shortcode functionality, which requires immediate attention.
Key Concerns
- Missing nonce checks on shortcodes
D3 Data Fields Security Vulnerabilities
D3 Data Fields Release Timeline
D3 Data Fields Code Analysis
Output Escaping
D3 Data Fields Attack Surface
Shortcodes 53
WordPress Hooks 3
Maintenance & Trust
D3 Data Fields Maintenance & Trust
Maintenance Signals
Community Trust
D3 Data Fields Alternatives
Sermon Manager Import
sermon-manager-import
Imports sermons into Sermon Manager using ID3 information.
WP Business Intelligence Lite
wp-business-intelligence-lite
Dynamic web charts and tables for your site! Connect to your live WordPress instance DB to retrieve data in real-time and update charts and tables!
LIQUID TREEMAP
liquid-treemap
Visualize the performance of the content in with TreeMap.
Power Charts – Responsive Beautiful Charts & Graphs
wpgo-power-charts-lite
Create highly responsive charts & graphs in WordPress with Power Charts using the advanced D3.js visualization library.
AudioTracks
audiotracks
Manage a directory of audio tracks in WordPress.
D3 Data Fields Developer Profile
3 plugins · 0 total installs
How We Detect D3 Data Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/d3-data-fields/d3-data-fields.js/wp-content/plugins/d3-data-fields/d3-data-fields.css?ver=/wp-content/plugins/d3-data-fields/d3-data-fields.js?ver=HTML / DOM Fingerprints
d3_data_fields_ajax_object[brand_name][business_company_name][first_name][last_name]