
Easy 3d Model Viewer Security & Risk Analysis
wordpress.org/plugins/easy-3d-model-viewerInteractive 3D model viewer with hotspots/markers, tooltips, animations, environment maps and realistic lighting.
Is Easy 3d Model Viewer Safe to Use in 2026?
Generally Safe
Score 100/100Easy 3d Model Viewer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'easy-3d-model-viewer' plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, all SQL queries are properly prepared, and all output is correctly escaped. There are also no recorded vulnerabilities (CVEs) for this plugin, which suggests a history of secure development or limited public scrutiny. The absence of file operations and external HTTP requests further reduces potential attack vectors.
However, significant concerns arise from the attack surface. The plugin exposes six AJAX handlers, with a concerning four of them lacking any authentication checks. This means that any user, including unauthenticated ones, could potentially interact with these handlers, opening the door to unauthorized actions. While taint analysis shows no critical or high severity issues, the lack of capability checks and only one nonce check across all entry points exacerbate the risk associated with the unprotected AJAX handlers.
In conclusion, while the plugin has strong foundations in secure coding for SQL and output handling, the large number of unprotected AJAX endpoints is a substantial security weakness. The vulnerability history is a positive indicator, but it cannot fully mitigate the immediate risks posed by the current code analysis. Addressing the authentication and authorization for the identified AJAX handlers is paramount to improving its security.
Key Concerns
- Unprotected AJAX handlers
- Missing capability checks
- Insufficient nonce checks
Easy 3d Model Viewer Security Vulnerabilities
Easy 3d Model Viewer Code Analysis
Output Escaping
Easy 3d Model Viewer Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Easy 3d Model Viewer Maintenance & Trust
Maintenance Signals
Community Trust
Easy 3d Model Viewer Alternatives
3D Viewer – Display Interactive 3D Models
3d-viewer
3D Viewer lets you embed interactive 3D models and 360 product views on WordPress sites with support for GLB, GLTF, OBJ, STL, FBX, DAE, and BIM.
3D Product Viewer & WebAR for WooCommerce
wc-product-3d-viewer
The Viraview plugin allows your Woocommerce powered webshop to display your products in 3D & WebAR for PC, Android and Apple.
3D Scan & Show: Product Viewer
3d-scan-and-show
Show your products and spaces in 3D. No code needed.
Emb3D Model Viewer
emb3d-model-viewer
A 3D model viewer for Elementor and WooCommerce
Kento 3D Model Viewer
kento-3d-model-viewer
Display 3D model on wordPress page, post, or custom page, 3D model rotate, zooming enabled.
Easy 3d Model Viewer Developer Profile
7 plugins · 80 total installs
How We Detect Easy 3d Model Viewer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-3d-model-viewer/css/fwdemv-front.css/wp-content/plugins/easy-3d-model-viewer/css/fwdemv-admin.css/wp-content/plugins/easy-3d-model-viewer/js/fwdemv-front.js/wp-content/plugins/easy-3d-model-viewer/js/fwdemv-admin.js/wp-content/plugins/easy-3d-model-viewer/js/lib/three.min.js/wp-content/plugins/easy-3d-model-viewer/js/lib/GLTFLoader.js/wp-content/plugins/easy-3d-model-viewer/js/lib/OrbitControls.js/wp-content/plugins/easy-3d-model-viewer/js/fwdemv-front.js/wp-content/plugins/easy-3d-model-viewer/js/lib/three.min.js/wp-content/plugins/easy-3d-model-viewer/js/lib/GLTFLoader.js/wp-content/plugins/easy-3d-model-viewer/js/lib/OrbitControls.js/wp-content/plugins/easy-3d-model-viewer/js/fwdemv-admin.js/wp-content/plugins/easy-3d-model-viewer/css/fwdemv-front.css?ver=/wp-content/plugins/easy-3d-model-viewer/css/fwdemv-admin.css?ver=/wp-content/plugins/easy-3d-model-viewer/js/fwdemv-front.js?ver=/wp-content/plugins/easy-3d-model-viewer/js/lib/three.min.js?ver=/wp-content/plugins/easy-3d-model-viewer/js/lib/GLTFLoader.js?ver=/wp-content/plugins/easy-3d-model-viewer/js/lib/OrbitControls.js?ver=/wp-content/plugins/easy-3d-model-viewer/js/fwdemv-admin.js?ver=HTML / DOM Fingerprints
fwdemv-canvas-containerfwdemv-model-wrapdata-model-idFWDEMV[fwdemv id="