
Material3d Security & Risk Analysis
wordpress.org/plugins/material3dMaterial3d is a platform provides a WYSIWYG way to construct and run interactive 3d scenes on web browsers with VR (Virtual Reality) device support.
Is Material3d Safe to Use in 2026?
Generally Safe
Score 85/100Material3d has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The material3d plugin v1.0.0 exhibits a mixed security posture. While it boasts a lack of known vulnerabilities and no dangerous functions or file operations, significant concerns arise from its attack surface. A high proportion of its entry points, specifically 5 out of 6, lack authentication checks, presenting a substantial risk of unauthorized access and manipulation. Furthermore, the output escaping is alarmingly low, with only 10% of outputs properly escaped, indicating a strong potential for cross-site scripting (XSS) vulnerabilities.
The taint analysis, though limited in scope, did identify one flow with unsanitized paths, which, combined with the lack of output escaping, further amplifies the XSS risk. The SQL query practices are decent with over half using prepared statements, but the remaining queries could still be susceptible to SQL injection if not handled carefully. The vulnerability history being clean is positive, suggesting a developer who may be responsive to security, but it does not negate the immediate risks identified in the code analysis.
In conclusion, the material3d plugin has foundational security strengths by avoiding known CVEs and dangerous functions. However, the unprotected attack surface and poor output sanitization are critical weaknesses that require immediate attention. The plugin's security is compromised by the ease with which an attacker could potentially exploit its functionalities due to the lack of proper authorization and output validation.
Key Concerns
- High number of unprotected AJAX handlers
- Low output escaping percentage
- Flow with unsanitized paths in taint analysis
- 5 AJAX handlers without authorization
Material3d Security Vulnerabilities
Material3d Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Material3d Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Material3d Maintenance & Trust
Maintenance Signals
Community Trust
Material3d Alternatives
Blocks Animation: CSS Animations for Gutenberg Blocks
blocks-animation
Blocks Animation allows you to add CSS Animations to all of your Gutenberg blocks in the most elegant way.
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress
wpvr
Create stunning 360 virtual tours to impress visitors and get more clients using WPVR - the easiest virtual tour creator in WordPress.
Better Block Editor (BBE)
better-block-editor
Better Block Editor (BBE) — responsive layout controls, on-scroll animations, and pre-made site templates for Block Editor.
MomentoPress for Momento360
cmyee-momentopress
Add 360° VR photos and videos easily to your WordPress site using MomentoPress for Momento360.
AKDev Spline animation – Delight your users experience with 3d scroll animations.
akdev-spline-animation
Create Spline 3d scrolling animations with ease and wow your users.
Material3d Developer Profile
1 plugin · 10 total installs
How We Detect Material3d
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/material3d/css/admin.css/wp-content/plugins/material3d/css/editor-ad.css/wp-content/plugins/material3d/css/editor.css/wp-content/plugins/material3d/css/scenes.css/wp-content/plugins/material3d/views/js/scenes.js/wp-content/plugins/material3d/views/js/scenes.js/wp-content/plugins/material3d/css/admin.css?ver=/wp-content/plugins/material3d/css/editor-ad.css?ver=/wp-content/plugins/material3d/css/editor.css?ver=/wp-content/plugins/material3d/css/scenes.css?ver=/wp-content/plugins/material3d/views/js/scenes.js?ver=HTML / DOM Fingerprints
m3d_scenelistm3d_playerdata-toggle="tab"m3d_scenelistm3d_player