
3D Product configurator for WooCommerce Security & Risk Analysis
wordpress.org/plugins/expiviEasy-to-use 3D product configurator to show your products in 360°
Is 3D Product configurator for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/1003D Product configurator for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The Expivi plugin version 2.15.6 presents a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of output escaping, significant concerns arise from its attack surface. The presence of 17 AJAX handlers, with two lacking authentication checks, exposes potential entry points for unauthorized actions. The absence of capability checks further exacerbates this risk, meaning any user, regardless of their role, could potentially trigger these unprotected AJAX actions.
The static analysis did not reveal any critical or high severity taint flows, which is a positive sign. However, the lack of taint analysis flows analyzed (0 total) means this aspect of the code has not been thoroughly scrutinized for more subtle vulnerabilities. The plugin's vulnerability history shows one medium severity CVE related to path traversal, which was patched. This history, combined with the unprotected AJAX endpoints, suggests a pattern where input sanitization and authorization might be areas requiring more rigorous attention.
In conclusion, Expivi 2.15.6 has strengths in its database interaction and output handling. However, the unprotected AJAX handlers are a critical weakness that needs immediate attention. The limited taint analysis and the historical path traversal vulnerability indicate that input validation and proper authorization remain areas of concern for this plugin.
Key Concerns
- Unprotected AJAX handlers
- Lack of capability checks
- Bundled library Guzzle
- Bundled library dompdf
- Unsanitized output (20% of outputs)
- Medium severity CVE history
3D Product configurator for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Product Configurator for WooCommerce <= 1.2.31 - Arbitrary File Deletion
3D Product configurator for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
3D Product configurator for WooCommerce Attack Surface
AJAX Handlers 17
WordPress Hooks 62
Maintenance & Trust
3D Product configurator for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
3D Product configurator for WooCommerce Alternatives
AR for WordPress
ar-for-wordpress
Augmented Reality for WordPress lets you showcase 3D models in an interactive viewer and AR on iOS and Android, with no app downloads needed.
ArtPlacer Widget
artplacer-widget
Allow your visitors visualize how artworks look on walls as soon as they land on your website!
SwiftXR (3D/AR/VR) Viewer
swiftxr-3darvr-viewer
Easily enhance customer engagement with immersive 3D, AR, and VR experiences
AR for WooCommerce
ar-for-woocommerce
Augmented Reality for WooCommerce plugin lets you display 3D models and AR products directly in your store with no app required.
AR Play
ar-play
Show any 3D Model in augmented reality (AR) trough our Android and iOS app.
3D Product configurator for WooCommerce Developer Profile
1 plugin · 100 total installs
How We Detect 3D Product configurator for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/expivi/assets/css/expivi-admin-products.css/wp-content/plugins/expivi/assets/css/expivi-public.css/wp-content/plugins/expivi/assets/js/expivi-admin-products.js/wp-content/plugins/expivi/assets/js/expivi-public.js/wp-content/plugins/expivi/assets/js/expivi-admin-order-manager.js/wp-content/plugins/expivi/assets/js/expivi-admin-products-list.js/wp-content/plugins/expivi/assets/js/expivi-order-item-generator.js/wp-content/plugins/expivi/assets/js/expivi-admin-settings.js+3 more/wp-content/plugins/expivi/assets/js/expivi-public.jsexpivi/assets/css/expivi-admin-products.css?ver=expivi/assets/css/expivi-public.css?ver=expivi/assets/js/expivi-admin-products.js?ver=expivi/assets/js/expivi-public.js?ver=expivi/assets/js/expivi-admin-order-manager.js?ver=expivi/assets/js/expivi-admin-products-list.js?ver=expivi/assets/js/expivi-order-item-generator.js?ver=expivi/assets/js/expivi-admin-settings.js?ver=HTML / DOM Fingerprints
expivi-product-configuratorexpivi-admin-product-list-tableexpivi-admin-product-list-itemexpivi-order-item-generated-productexpivi-admin-order-item-columnexpivi-admin-order-retry-prf-buttonexpivi-admin-settings-section<!-- Expivi Admin Order Manager Start --><!-- Expivi Admin Order Manager End --><!-- Expivi Admin Product List Table Header --><!-- Expivi Admin Product List Table Data -->+2 moredata-expivi-product-iddata-expivi-configurationdata-expivi-order-item-iddata-expivi-dynamic-skudata-expivi-print-ready-hashmapwindow.expiviConfiguratorwindow.expiviAdminProductswindow.expiviOrderItemGeneratorwindow.ExpiviAdminSettingsexpivi_ajax_object/wp-json/expivi/v1/products/wp-json/expivi/v1/configurations[expivi_product_configurator][expivi_gallery][expivi_viewer]