Kento 3D Model Viewer Security & Risk Analysis

wordpress.org/plugins/kento-3d-model-viewer

Display 3D model on wordPress page, post, or custom page, 3D model rotate, zooming enabled.

100 active installs v1.0 PHP + WP 3.5+ Updated Jun 9, 2015
3d-model-display3d-model-viewer3d-model-viewer-wordpress3ds-viewerobj-viewer
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kento 3D Model Viewer Safe to Use in 2026?

Generally Safe

Score 85/100

Kento 3D Model Viewer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The kento-3d-model-viewer plugin version 1.0 exhibits a strong security posture based on the provided static analysis. The code demonstrates excellent adherence to secure coding practices by implementing prepared statements for all SQL queries and ensuring proper output escaping. The absence of file operations, external HTTP requests, and dangerous functions further mitigates common attack vectors. Crucially, the plugin's attack surface is minimal, with only one shortcode, and no AJAX handlers or REST API routes were detected, meaning there are no apparent unauthenticated entry points into the plugin's functionality.

This pristine code analysis, combined with a complete lack of documented vulnerability history, suggests a well-developed and secure plugin at this version. There are no critical or high severity taint flows, and the absence of recorded CVEs indicates a history of responsible development or a lack of past exploitation. While the plugin appears secure, the limited scope of the analysis (e.g., 0 flows analyzed in taint analysis) means there's always a possibility of undiscovered issues. However, based on the available data, this plugin presents a very low security risk.

Vulnerabilities
None known

Kento 3D Model Viewer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Kento 3D Model Viewer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Kento 3D Model Viewer Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[kento_3dmv] index.php:59
WordPress Hooks 3
actioninitindex.php:21
filtermce_external_pluginsindex.php:68
filtermce_buttonsindex.php:69
Maintenance & Trust

Kento 3D Model Viewer Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJun 9, 2015
PHP min version
Downloads9K

Community Trust

Rating74/100
Number of ratings9
Active installs100
Developer Profile

Kento 3D Model Viewer Developer Profile

PluginsPoint

20 plugins · 600 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Kento 3D Model Viewer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kento-3d-model-viewer/scripts/jsc3d.js/wp-content/plugins/kento-3d-model-viewer/scripts/editor_plugin.js
Script Paths
/wp-content/plugins/kento-3d-model-viewer/scripts/jsc3d.js

HTML / DOM Fingerprints

Data Attributes
id='cv'class='kento_3dmv_mce_button'
JS Globals
JSC3D.Viewer
Shortcode Output
<div style='width: id='cv' style='border: 1px solid;' width='' height='
FAQ

Frequently Asked Questions about Kento 3D Model Viewer