DXFViewer Security & Risk Analysis

wordpress.org/plugins/dxfview

This plugin displays a DXF file on your Wordpress post or page.

30 active installs v1.0 PHP + WP 4.5.4+ Updated Oct 20, 2016
dxf
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is DXFViewer Safe to Use in 2026?

Generally Safe

Score 85/100

DXFViewer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The dxfview plugin v1.0 presents a mixed security profile. On the positive side, the static analysis indicates a small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no recorded vulnerabilities (CVEs) in its history, suggesting a relatively stable and well-maintained code base. The plugin also appears to utilize prepared statements for its SQL queries, which is a good practice for preventing SQL injection. However, a significant concern arises from the complete lack of output escaping. This means that any data rendered by the plugin could potentially be vulnerable to cross-site scripting (XSS) attacks if it processes or displays user-supplied input without proper sanitization. Additionally, the absence of nonce and capability checks on any potential entry points (even though none were detected) is a weakness. While the attack surface is currently zero, if future versions introduce new functionalities that become entry points, these checks will be critical.

Key Concerns

  • No output escaping
  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

DXFViewer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

DXFViewer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Attack Surface

DXFViewer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninitsettings\DXFViewSettings.php:14
actionadmin_initsettings\DXFViewSettings.php:18
actionadmin_menusettings\DXFViewSettings.php:19
Maintenance & Trust

DXFViewer Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedOct 20, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Alternatives

DXFViewer Alternatives

No alternatives data available yet.

Developer Profile

DXFViewer Developer Profile

aviket

2 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DXFViewer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dxfview/js//wp-content/plugins/dxfview/css/
Script Paths
/wp-content/plugins/dxfview/js/dxfviewer.js/wp-content/plugins/dxfview/js/three.min.js/wp-content/plugins/dxfview/js/TrackballControls.js/wp-content/plugins/dxfview/js/STLLoader.js
Version Parameters
dxfview/js/dxfviewer.js?ver=dxfview/js/three.min.js?ver=dxfview/js/TrackballControls.js?ver=dxfview/js/STLLoader.js?ver=dxfview/css/dxfviewer.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about DXFViewer