
DXFViewer Security & Risk Analysis
wordpress.org/plugins/dxfviewThis plugin displays a DXF file on your Wordpress post or page.
Is DXFViewer Safe to Use in 2026?
Generally Safe
Score 85/100DXFViewer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The dxfview plugin v1.0 presents a mixed security profile. On the positive side, the static analysis indicates a small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no recorded vulnerabilities (CVEs) in its history, suggesting a relatively stable and well-maintained code base. The plugin also appears to utilize prepared statements for its SQL queries, which is a good practice for preventing SQL injection. However, a significant concern arises from the complete lack of output escaping. This means that any data rendered by the plugin could potentially be vulnerable to cross-site scripting (XSS) attacks if it processes or displays user-supplied input without proper sanitization. Additionally, the absence of nonce and capability checks on any potential entry points (even though none were detected) is a weakness. While the attack surface is currently zero, if future versions introduce new functionalities that become entry points, these checks will be critical.
Key Concerns
- No output escaping
- No nonce checks detected
- No capability checks detected
DXFViewer Security Vulnerabilities
DXFViewer Code Analysis
Output Escaping
DXFViewer Attack Surface
WordPress Hooks 3
Maintenance & Trust
DXFViewer Maintenance & Trust
Maintenance Signals
Community Trust
DXFViewer Alternatives
No alternatives data available yet.
DXFViewer Developer Profile
2 plugins · 40 total installs
How We Detect DXFViewer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dxfview/js//wp-content/plugins/dxfview/css//wp-content/plugins/dxfview/js/dxfviewer.js/wp-content/plugins/dxfview/js/three.min.js/wp-content/plugins/dxfview/js/TrackballControls.js/wp-content/plugins/dxfview/js/STLLoader.jsdxfview/js/dxfviewer.js?ver=dxfview/js/three.min.js?ver=dxfview/js/TrackballControls.js?ver=dxfview/js/STLLoader.js?ver=dxfview/css/dxfviewer.css?ver=