
Site3D Configurator Security & Risk Analysis
wordpress.org/plugins/site3d-configuratorInsert a shortcode to embed interactive 3D configurators from Site3D on any page or post.
Is Site3D Configurator Safe to Use in 2026?
Generally Safe
Score 100/100Site3D Configurator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "site3d-configurator" plugin v0.1 exhibits a generally good security posture based on the provided static analysis. It correctly utilizes prepared statements for all SQL queries and includes nonce and capability checks, which are fundamental security practices. The absence of dangerous functions, file operations, external HTTP requests, and any recorded historical vulnerabilities further contributes to this positive assessment. However, a notable concern is the incomplete output escaping, with only 50% of identified outputs being properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if unsanitized data is rendered directly in the front-end.
While the attack surface is relatively small and all identified entry points appear to have some form of authentication or permission check, the 50% output escaping rate is a significant weakness that needs to be addressed. The plugin's clean vulnerability history suggests a proactive or perhaps less-targeted development approach thus far. Overall, the plugin has strong foundations but requires attention to its output sanitization to mitigate potential XSS risks.
Key Concerns
- Half of outputs not properly escaped
Site3D Configurator Security Vulnerabilities
Site3D Configurator Release Timeline
Site3D Configurator Code Analysis
Output Escaping
Site3D Configurator Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Site3D Configurator Maintenance & Trust
Maintenance Signals
Community Trust
Site3D Configurator Alternatives
Reusable Blocks Extended
reusable-blocks-extended
Extend Gutenberg Reusable Blocks feature with a complete admin panel, widgets, shortcodes and PHP functions.
Webcomic
webcomic
Comic publishing power for the web. Turn your WordPress-powered site into a comic publishing platform with Webcomic.
Floating Video Widget
floating-video-widget
Add a customizable floating video widget to any page or post using a simple shortcode.
Bamboo Social
bamboo-social
This plugin provides a widget and a shortcode for generating social media icons that link to the relevent social media accounts.
EM Social Media
em-social-media
Allows you to add links to your social media pages/profiles via widget or shortcode.
Site3D Configurator Developer Profile
1 plugin · 10 total installs
How We Detect Site3D Configurator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/site3d-configurator/css/admin-style.css/wp-content/plugins/site3d-configurator/js/admin-scripts.jssite3d-configurator/js/admin-scripts.js?ver=HTML / DOM Fingerprints
site3dsite3d__headersite3d__textsite3d__text--bigsite3d__framesite3d__frame-contentsite3d__text--no-marginsite3d__input+12 moredata-site3ddata-langid="site3d-configurator-load"name="id-input"class="site3d__input site3d__input--text"value="0"+15 moreSite3DAdminJsSite3DAdminJs_obj/wp-json/site3d/v1/ajax_convert[site3d