Simplio3D Product Configurator Security & Risk Analysis

wordpress.org/plugins/simplio3d-product-configurator

Simplio3D Product Configurator embeds your Simplio3D configurator and adds configured products to the WooCommerce cart.

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Jan 6, 2026
3d-configuratorarcpqproduct-configuratorproduct-customizer
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simplio3D Product Configurator Safe to Use in 2026?

Generally Safe

Score 100/100

Simplio3D Product Configurator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "simplio3d-product-configurator" plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. All identified entry points (AJAX handlers, shortcodes) appear to be protected with the necessary checks, as indicated by the absence of unprotected entry points. The code demonstrates excellent security practices by not using dangerous functions, executing SQL queries exclusively through prepared statements, and properly escaping all output. The absence of file operations and external HTTP requests further reduces the attack surface and potential for common vulnerabilities.

However, a significant concern arises from the complete lack of capability checks. While nonce checks are present for one entry point, the absence of capability checks for AJAX handlers and shortcodes means that any authenticated user, regardless of their role or permissions, could potentially trigger these functionalities. This could lead to privilege escalation if these actions were intended for specific user roles. The taint analysis showing zero flows, while seemingly positive, could also be an indicator of insufficient analysis depth or lack of complex data handling within the plugin that might otherwise reveal vulnerabilities.

Given the plugin's current lack of documented vulnerabilities and its good coding practices in areas like prepared statements and output escaping, its historical security record is clean. This, combined with the controlled entry points, suggests a generally well-developed plugin. Nevertheless, the critical oversight of missing capability checks represents a notable weakness that could be exploited in certain scenarios, making a complete security assessment reliant on understanding the exact functionality of the AJAX handlers and shortcodes.

Key Concerns

  • Missing capability checks for entry points
Vulnerabilities
None known

Simplio3D Product Configurator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Simplio3D Product Configurator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
22 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped22 total outputs
Attack Surface

Simplio3D Product Configurator Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_simplio3d_add_to_cartsimplio3d-product-configurator.php:29
noprivwp_ajax_simplio3d_add_to_cartsimplio3d-product-configurator.php:30

Shortcodes 1

[simplio3d_configurator] simplio3d-product-configurator.php:45
WordPress Hooks 9
actionwp_enqueue_scriptssimplio3d-product-configurator.php:28
filterwoocommerce_get_item_datasimplio3d-product-configurator.php:33
filterwoocommerce_cart_item_thumbnailsimplio3d-product-configurator.php:34
filterwoocommerce_get_cart_item_from_sessionsimplio3d-product-configurator.php:35
filterwoocommerce_cart_item_namesimplio3d-product-configurator.php:36
actionwoocommerce_before_calculate_totalssimplio3d-product-configurator.php:39
actionwoocommerce_checkout_create_order_line_itemsimplio3d-product-configurator.php:42
filterwoocommerce_order_item_namesimplio3d-product-configurator.php:47
filterwoocommerce_store_api_cart_itemsimplio3d-product-configurator.php:57
Maintenance & Trust

Simplio3D Product Configurator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 6, 2026
PHP min version7.4
Downloads135

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Simplio3D Product Configurator Developer Profile

Digital Artflow

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simplio3D Product Configurator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simplio3d-product-configurator/assets/js/simplio3d-woo.js
Script Paths
assets/js/simplio3d-woo.js
Version Parameters
simplio3d-product-configurator/assets/js/simplio3d-woo.js?ver=

HTML / DOM Fingerprints

CSS Classes
simplio3d-wrappersimplio3d-iframe
Data Attributes
data-product-id
JS Globals
Simplio3DWoo
Shortcode Output
<div class="simplio3d-wrapper" data-product-id="
FAQ

Frequently Asked Questions about Simplio3D Product Configurator