
Planet Pop Security & Risk Analysis
wordpress.org/plugins/planet-popInteractive 3D planet viewer with hotspots, tooltips, animations, environment maps and realistic lighting.
Is Planet Pop Safe to Use in 2026?
Generally Safe
Score 100/100Planet Pop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "planet-pop" v1.0 plugin exhibits a generally strong security posture, with several key positive indicators. Notably, all SQL queries utilize prepared statements, and all output is properly escaped, which are fundamental security practices. The absence of dangerous functions, file operations, external HTTP requests, and the use of a single nonce check also contribute positively. However, a significant concern arises from the presence of 6 AJAX handlers, of which 4 lack authentication checks. This creates a substantial attack surface that could be exploited by unauthenticated users. While there is no recorded vulnerability history or taint analysis findings, the unprotected AJAX endpoints represent a critical, albeit currently theoretical, risk that demands attention. The plugin demonstrates good coding practices in critical areas like SQL and output handling, but the unprotected AJAX handlers significantly detract from its overall security.
Key Concerns
- 4 AJAX handlers without authentication
- Only 1 nonce check for 7 entry points
- Only 1 capability check for 7 entry points
Planet Pop Security Vulnerabilities
Planet Pop Code Analysis
Output Escaping
Planet Pop Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Planet Pop Maintenance & Trust
Maintenance Signals
Community Trust
Planet Pop Alternatives
Imsanity
imsanity
Automatically resizes huge image uploads. Are contributors uploading huge photos? Tired of manually resizing your images? Imsanity to the rescue!
3D Viewer – Display Interactive 3D Models
3d-viewer
3D Viewer lets you embed interactive 3D models and 360 product views on WordPress sites with support for GLB, GLTF, OBJ, STL, FBX, DAE, and BIM.
FakerPress
fakerpress
FakerPress is a clean way to generate fake and dummy content to your WordPress, great for developers who need testing
PNG to JPG
png-to-jpg
Convert PNG images to JPG, free up web space and speed up your webpage
Disk Usage Sunburst
disk-usage-sunburst
Visualize and drill down the disk usage of your whole WordPress installation. Find and identify big files immediately!
Planet Pop Developer Profile
7 plugins · 80 total installs
How We Detect Planet Pop
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/planet-pop/js/admin.js/wp-content/plugins/planet-pop/js/fwdpp.js/wp-content/plugins/planet-pop/js/fwdpp.public.js/wp-content/plugins/planet-pop/css/admin.css/wp-content/plugins/planet-pop/css/fwdpp.css/wp-content/plugins/planet-pop/js/admin.js/wp-content/plugins/planet-pop/js/fwdpp.js/wp-content/plugins/planet-pop/js/fwdpp.public.jsplanet-pop/js/admin.js?ver=planet-pop/js/fwdpp.js?ver=planet-pop/js/fwdpp.public.js?ver=planet-pop/css/admin.css?ver=planet-pop/css/fwdpp.css?ver=HTML / DOM Fingerprints
fwdpp-viewer-wrapfwdpp-admin-menu-wrapdata-fwdpp-idfwdpp_optionsfwdpp_admin_options/wp-json/planet-pop/v1/get-planets/wp-json/planet-pop/v1/save-planets/wp-json/planet-pop/v1/get-css/wp-json/planet-pop/v1/set-css[fwdpp