Site3D Configurator Security & Risk Analysis

wordpress.org/plugins/site3d-configurator

Insert a shortcode to embed interactive 3D configurators from Site3D on any page or post.

10 active installs v0.1 PHP 7.4+ WP 5.8+ Updated Mar 21, 2026
blockscustomizationmediashortcodewidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Site3D Configurator Safe to Use in 2026?

Generally Safe

Score 100/100

Site3D Configurator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "site3d-configurator" plugin v0.1 exhibits a generally good security posture based on the provided static analysis. It correctly utilizes prepared statements for all SQL queries and includes nonce and capability checks, which are fundamental security practices. The absence of dangerous functions, file operations, external HTTP requests, and any recorded historical vulnerabilities further contributes to this positive assessment. However, a notable concern is the incomplete output escaping, with only 50% of identified outputs being properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if unsanitized data is rendered directly in the front-end.

While the attack surface is relatively small and all identified entry points appear to have some form of authentication or permission check, the 50% output escaping rate is a significant weakness that needs to be addressed. The plugin's clean vulnerability history suggests a proactive or perhaps less-targeted development approach thus far. Overall, the plugin has strong foundations but requires attention to its output sanitization to mitigate potential XSS risks.

Key Concerns

  • Half of outputs not properly escaped
Vulnerabilities
None known

Site3D Configurator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Site3D Configurator Release Timeline

v0.1Current
Code Analysis
Analyzed Apr 16, 2026

Site3D Configurator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface

Site3D Configurator Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_site3d_ajax_convertsite3d-configurator.php:66
noprivwp_ajax_site3d_ajax_convertsite3d-configurator.php:67

Shortcodes 1

[site3d] site3d-configurator.php:38
WordPress Hooks 5
actionadmin_menuinc/admin-mainpage.php:18
actionplugins_loadedsite3d-configurator.php:25
actionwp_print_footer_scriptssite3d-configurator.php:40
actioninitsite3d-configurator.php:60
actionadmin_enqueue_scriptssite3d-configurator.php:68
Maintenance & Trust

Site3D Configurator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 21, 2026
PHP min version7.4
Downloads964

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Site3D Configurator Developer Profile

site3d

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Site3D Configurator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/site3d-configurator/css/admin-style.css
Script Paths
/wp-content/plugins/site3d-configurator/js/admin-scripts.js
Version Parameters
site3d-configurator/js/admin-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
site3dsite3d__headersite3d__textsite3d__text--bigsite3d__framesite3d__frame-contentsite3d__text--no-marginsite3d__input+12 more
Data Attributes
data-site3ddata-langid="site3d-configurator-load"name="id-input"class="site3d__input site3d__input--text"value="0"+15 more
JS Globals
Site3DAdminJsSite3DAdminJs_obj
REST Endpoints
/wp-json/site3d/v1/ajax_convert
Shortcode Output
[site3d
FAQ

Frequently Asked Questions about Site3D Configurator