PausAR – 3D and AR Viewer Metrics Security & Risk Analysis

wordpress.org/plugins/pausar-metrics

Understand how visitors interact with your PausAR 3D & AR content – lightweight, no cookies, no personal data.

10 active installs v1.0.7 PHP 7.4+ WP 5.8+ Updated Mar 22, 2026
3d3d-vieweranalyticsaraugmented-reality
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PausAR – 3D and AR Viewer Metrics Safe to Use in 2026?

Generally Safe

Score 100/100

PausAR – 3D and AR Viewer Metrics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "pausar-metrics" v1.0.7 plugin demonstrates several positive security practices, including the exclusive use of prepared statements for all SQL queries and proper output escaping for all outputs, indicating a good understanding of fundamental security principles. The absence of known vulnerabilities and common vulnerability types in its history is also a strong indicator of a relatively secure codebase. However, a significant concern arises from the presence of one unprotected REST API route, which represents a direct entry point into the application without any authentication or authorization checks. This lack of protection on an exposed endpoint is a critical oversight. Furthermore, the taint analysis revealed one flow with an unsanitized path, classified as high severity, which could potentially lead to unintended behavior or vulnerabilities if not addressed. While the plugin avoids dangerous functions and file operations, and has a reasonable number of nonce and capability checks, the unprotected REST API route and the high-severity taint flow are significant weaknesses that expose the application to potential risks.

Key Concerns

  • Unprotected REST API route
  • High severity unsanitized path taint flow
Vulnerabilities
None known

PausAR – 3D and AR Viewer Metrics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

PausAR – 3D and AR Viewer Metrics Release Timeline

v1.0.7Current
Code Analysis
Analyzed Apr 16, 2026

PausAR – 3D and AR Viewer Metrics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
36 prepared
Unescaped Output
1
239 escaped
Nonce Checks
6
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared36 total queries

Output Escaping

100% escaped240 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

5 flows1 with unsanitized paths
pausar_analytics_handle_post_actions (includes/plugin-core.php:591)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

PausAR – 3D and AR Viewer Metrics Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

POST/wp-json/pausar-metrics/v1/trackincludes/plugin-core.php:284
WordPress Hooks 15
actionadmin_noticesincludes/plugin-core.php:33
actionplugins_loadedincludes/plugin-core.php:126
actionpausar_analytics_daily_cleanupincludes/plugin-core.php:151
actioninitincludes/plugin-core.php:161
actionwp_dashboard_setupincludes/plugin-core.php:169
actionrest_api_initincludes/plugin-core.php:283
actiontemplate_redirectincludes/plugin-core.php:390
actionwp_enqueue_scriptsincludes/plugin-core.php:453
actionadmin_initincludes/plugin-core.php:590
actionadmin_menuincludes/plugin-core.php:673
actionadmin_enqueue_scriptsincludes/plugin-core.php:704
actionadmin_enqueue_scriptsincludes/plugin-core.php:716
filterplugin_row_metaincludes/plugin-core.php:737
filterplugin_iconpausar-metrics.php:92
actionafter_uninstallpausar-metrics.php:110

Scheduled Events 1

pausar_analytics_daily_cleanup
Maintenance & Trust

PausAR – 3D and AR Viewer Metrics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 22, 2026
PHP min version7.4
Downloads107

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

PausAR – 3D and AR Viewer Metrics Developer Profile

PausAR Studio

2 plugins · 310 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PausAR – 3D and AR Viewer Metrics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pausar-metrics/assets/css/pausar-metrics.css/wp-content/plugins/pausar-metrics/assets/js/pausar-metrics.js
Script Paths
/wp-content/plugins/pausar-metrics/assets/js/pausar-metrics.js
Version Parameters
pausar-metrics/assets/css/pausar-metrics.css?ver=pausar-metrics/assets/js/pausar-metrics.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- PausAR Metrics: Data stored in pausar_metrics_data. --><!-- PausAR Metrics: Analytics script. -->
Data Attributes
data-pausar-metrics-iddata-pausar-metrics-event
JS Globals
window.pausarMetricsvar pausarMetrics
FAQ

Frequently Asked Questions about PausAR – 3D and AR Viewer Metrics