Embed STL Security & Risk Analysis

wordpress.org/plugins/embed-stl

Adds STL as a media type for uploads, provides editor block for embeddable viewer based on viewstl plugin.

400 active installs v1.0.2 PHP 7.0+ WP 6.3+ Updated Feb 4, 2026
3dblockstl
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Embed STL Safe to Use in 2026?

Generally Safe

Score 100/100

Embed STL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'embed-stl' plugin v1.0.2 appears to have a generally good security posture with no immediately obvious critical vulnerabilities present in the code. The absence of dangerous functions, file operations, and external HTTP requests is a strong positive indicator. Furthermore, the fact that all SQL queries utilize prepared statements is excellent practice. The output escaping rate is also very high, suggesting a good effort to prevent XSS vulnerabilities. The vulnerability history being entirely clear further reinforces this initial positive assessment, indicating a lack of known past security issues that could resurface.

Key Concerns

  • Lack of Nonce Checks
  • Lack of Capability Checks
Vulnerabilities
None known

Embed STL Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Embed STL Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
19 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped20 total outputs
Attack Surface

Embed STL Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitindex.php:19
actioninitindex.php:20
filterupload_mimesindex.php:21
filterpost_mime_typesindex.php:22
Maintenance & Trust

Embed STL Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 4, 2026
PHP min version7.0
Downloads5K

Community Trust

Rating90/100
Number of ratings2
Active installs400
Developer Profile

Embed STL Developer Profile

mmdoogie

1 plugin · 400 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Embed STL

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/embed-stl/public/js/stl_viewer.min.js/wp-content/plugins/embed-stl/public/img/icon.svg
Script Paths
/wp-content/plugins/embed-stl/public/js/stl_viewer.min.js

HTML / DOM Fingerprints

CSS Classes
embed-stl-targetembed-stl-size-embed-stl-yes-borderembed-stl-cube-icon
Data Attributes
data-block-iddata-block-sizedata-show-borderdata-hide-overlay-icondata-media-urldata-model-color+9 more
JS Globals
stl_viewer_script_pathStlViewer
Shortcode Output
<div class="embed-stl-target embed-stl-size-<img src="class="embed-stl-cube-icon">var stlView_
FAQ

Frequently Asked Questions about Embed STL