D3 Data Fields Security & Risk Analysis

wordpress.org/plugins/d3-data-fields

Create WordPress data fields and allows data access by shortcodes.

0 active installs v0.1 PHP 8.0+ WP 5.0+ Updated Apr 15, 2023
d3d3-data-fields
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is D3 Data Fields Safe to Use in 2026?

Generally Safe

Score 85/100

D3 Data Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "d3-data-fields" v0.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the proper escaping of all output signals robust development practices. Furthermore, the lack of file operations and external HTTP requests minimizes potential attack vectors. The presence of a capability check, albeit only one, is a positive sign for access control.

However, the analysis reveals a notable concern: the complete absence of nonce checks across all entry points, particularly the 53 shortcodes. While there are no critical taint flows or unpatched vulnerabilities historically, this omission creates a significant risk for Cross-Site Request Forgery (CSRF) attacks. Attackers could potentially trick authenticated users into executing unintended actions via these shortcodes if they lack sufficient user input validation or capability checks beyond the single observed instance.

The vulnerability history being clear of any recorded CVEs is highly encouraging and suggests a history of secure development or minimal exposure. Nevertheless, the absence of historical issues should not be interpreted as a guarantee of current security, especially given the identified absence of nonce checks. In conclusion, the plugin demonstrates good foundational security but has a critical oversight regarding nonce protection for its shortcode functionality, which requires immediate attention.

Key Concerns

  • Missing nonce checks on shortcodes
Vulnerabilities
None known

D3 Data Fields Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

D3 Data Fields Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

D3 Data Fields Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
68 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped68 total outputs
Attack Surface

D3 Data Fields Attack Surface

Entry Points53
Unprotected0

Shortcodes 53

[brand_name] d3-data-fields.php:1279
[business_company_name] d3-data-fields.php:1280
[first_name] d3-data-fields.php:1281
[last_name] d3-data-fields.php:1282
[tax_code] d3-data-fields.php:1283
[vat_number] d3-data-fields.php:1284
[pec] d3-data-fields.php:1285
[sdi] d3-data-fields.php:1286
[business_register] d3-data-fields.php:1287
[rea] d3-data-fields.php:1288
[address] d3-data-fields.php:1289
[zip] d3-data-fields.php:1290
[city] d3-data-fields.php:1291
[province_canton_state] d3-data-fields.php:1292
[country] d3-data-fields.php:1293
[phone_primary] d3-data-fields.php:1294
[phone_secondary] d3-data-fields.php:1295
[technical_office_phone] d3-data-fields.php:1296
[commercial_office_phone] d3-data-fields.php:1297
[accounting_office_phone] d3-data-fields.php:1298
[human_resources_office_phone] d3-data-fields.php:1299
[warehouse_phone] d3-data-fields.php:1300
[email_primary] d3-data-fields.php:1301
[email_secondary] d3-data-fields.php:1302
[website_primary] d3-data-fields.php:1303
[website_secondary] d3-data-fields.php:1304
[headquarters_iframe_map] d3-data-fields.php:1305
[resellers_iframe_map] d3-data-fields.php:1306
[facebook] d3-data-fields.php:1307
[instagram] d3-data-fields.php:1308
[whatsapp] d3-data-fields.php:1309
[linkedin] d3-data-fields.php:1310
[youtube] d3-data-fields.php:1311
[tiktok] d3-data-fields.php:1312
[behance] d3-data-fields.php:1313
[pinterest] d3-data-fields.php:1314
[tumblr] d3-data-fields.php:1315
[telegram] d3-data-fields.php:1316
[twitter] d3-data-fields.php:1317
[google] d3-data-fields.php:1318
[snapchat] d3-data-fields.php:1319
[dribbble] d3-data-fields.php:1320
[yahoo] d3-data-fields.php:1321
[reddit] d3-data-fields.php:1322
[github] d3-data-fields.php:1323
[vimeo] d3-data-fields.php:1324
[vine] d3-data-fields.php:1325
[foursquare] d3-data-fields.php:1326
[flickr] d3-data-fields.php:1327
[rss] d3-data-fields.php:1328
[500px] d3-data-fields.php:1329
[wordpress] d3-data-fields.php:1330
[spotify] d3-data-fields.php:1331
WordPress Hooks 3
actionadmin_menud3-data-fields.php:1169
actionadmin_initd3-data-fields.php:1215
actionadmin_menud3-data-fields.php:1395
Maintenance & Trust

D3 Data Fields Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 15, 2023
PHP min version8.0
Downloads729

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

D3 Data Fields Developer Profile

Filippo

3 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect D3 Data Fields

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/d3-data-fields/d3-data-fields.js
Version Parameters
/wp-content/plugins/d3-data-fields/d3-data-fields.css?ver=/wp-content/plugins/d3-data-fields/d3-data-fields.js?ver=

HTML / DOM Fingerprints

JS Globals
d3_data_fields_ajax_object
Shortcode Output
[brand_name][business_company_name][first_name][last_name]
FAQ

Frequently Asked Questions about D3 Data Fields