3D Product Viewer & WebAR for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-product-3d-viewer

The Viraview plugin allows your Woocommerce powered webshop to display your products in 3D & WebAR for PC, Android and Apple.

10 active installs v1.0.5 PHP 5.2.4+ WP 5.6+ Updated Jul 25, 2023
360-deg-viewer360-product-viewer3d-model-display3d-model-viewer3d-viewer
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 3D Product Viewer & WebAR for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

3D Product Viewer & WebAR for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The wc-product-3d-viewer plugin v1.0.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has no known historical vulnerabilities. The attack surface is minimal, with only one shortcode and no unprotected entry points. However, the static analysis reveals significant concerns. The presence of the `unserialize` function is a critical risk, especially when not adequately protected by nonce checks or capability checks, as it can lead to remote code execution if crafted malicious data is passed. The taint analysis indicating unsanitized paths, although not classified as critical or high, suggests a potential for data leakage or manipulation if these paths are accessible and exploitable. The lack of nonce and capability checks across all identified entry points is a serious oversight, leaving the plugin vulnerable to cross-site request forgery and privilege escalation attacks. The 70% proper output escaping is also concerning, as the remaining 30% of unescaped output could be exploited for cross-site scripting vulnerabilities.

Key Concerns

  • Dangerous function 'unserialize' used
  • Taint analysis shows unsanitized paths
  • No nonce checks found
  • No capability checks found
  • 30% of output not properly escaped
Vulnerabilities
None known

3D Product Viewer & WebAR for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

3D Product Viewer & WebAR for WooCommerce Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
7
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Dangerous Functions Found

unserialize$var_res = unserialize( base64_decode( $nickx_lic ) );js\nickx_live.php:9
unserialize$nickx_lic = unserialize( base64_decode( $nickx_lic ) );js\nickx_live.php:44

Output Escaping

70% escaped23 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
woocommerce_product_custom_fields_save (3D-product-viewer-and-webAR-for-woocommerce.php:492)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

3D Product Viewer & WebAR for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[product_gallery_shortcode] 3D-product-viewer-and-webAR-for-woocommerce.php:85
WordPress Hooks 11
actionadmin_notices3D-product-viewer-and-webAR-for-woocommerce.php:79
actionadmin_menu3D-product-viewer-and-webAR-for-woocommerce.php:80
actionadmin_init3D-product-viewer-and-webAR-for-woocommerce.php:81
actionwp_enqueue_scripts3D-product-viewer-and-webAR-for-woocommerce.php:83
filterwc_get_template3D-product-viewer-and-webAR-for-woocommerce.php:86
actionplugins_loaded3D-product-viewer-and-webAR-for-woocommerce.php:294
actionwoocommerce_product_thumbnails3D-product-viewer-and-webAR-for-woocommerce.php:305
actionwoocommerce_before_single_product_summary3D-product-viewer-and-webAR-for-woocommerce.php:310
actionadmin_notices3D-product-viewer-and-webAR-for-woocommerce.php:313
actionwoocommerce_product_options_general_product_data3D-product-viewer-and-webAR-for-woocommerce.php:525
actionwoocommerce_process_product_meta3D-product-viewer-and-webAR-for-woocommerce.php:527
Maintenance & Trust

3D Product Viewer & WebAR for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.0
Last updatedJul 25, 2023
PHP min version5.2.4
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

3D Product Viewer & WebAR for WooCommerce Developer Profile

Virakle Technologies

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 3D Product Viewer & WebAR for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-product-3d-viewer/images/icon.png/wp-content/plugins/wc-product-3d-viewer/images/logo-virakle.png
Script Paths
js/nickx_live.php

HTML / DOM Fingerprints

CSS Classes
flex-container
Data Attributes
data-product_gallery_shortcode
Shortcode Output
<span id="product_gallery_shortcode">
FAQ

Frequently Asked Questions about 3D Product Viewer & WebAR for WooCommerce