
WP W3D plugin Security & Risk Analysis
wordpress.org/plugins/wp-w3dWP W3D aims to help WP users or developers to add easily several UI elements to their website, including 3D components and complex animated layouts.
Is WP W3D plugin Safe to Use in 2026?
Generally Safe
Score 85/100WP W3D plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-w3d plugin v0.1 presents a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and avoids external HTTP requests and file operations. The absence of known vulnerabilities and a clean taint analysis history are also encouraging signs. However, there are significant concerns regarding its attack surface and the handling of potentially dangerous functions.
The plugin exposes two AJAX handlers without authentication checks, creating a direct path for unauthenticated attackers to interact with the plugin's functionality. Furthermore, the presence of the `unserialize` function is a critical risk, especially when not paired with robust input validation and sanitization. While the taint analysis did not reveal any explicit unsanitized paths, the `unserialize` function itself is inherently dangerous and can lead to Remote Code Execution if used with user-supplied, untrusted data. The low percentage of properly escaped output (10%) also suggests a risk of Cross-Site Scripting (XSS) vulnerabilities.
Overall, while the plugin has a clean vulnerability history, the identified code signals and attack surface necessitate caution. The lack of authentication on AJAX endpoints and the use of `unserialize` are high-priority areas that require immediate attention to mitigate potential security risks.
Key Concerns
- Unprotected AJAX handlers
- Use of unserialize function
- Low percentage of properly escaped output
WP W3D plugin Security Vulnerabilities
WP W3D plugin Release Timeline
WP W3D plugin Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP W3D plugin Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 33
Maintenance & Trust
WP W3D plugin Maintenance & Trust
Maintenance Signals
Community Trust
WP W3D plugin Alternatives
Cinematic 3D Parallax Touch Slider
cinematic
Responsive 3D Parallax Touch Slider. The most realistic mobile 3D layer photo animation in the market.
Hot Blocks
hot-blocks
A collection of several blocks for new WordPress editor (Gutenberg).
Carousel 3D Slider
carousel-3d-slider
Configure a Responsive 3D jQuery Carousel Slider and Insert it in any Page or Post as a Shortcode.
Cube 3D Slider
cube-3d-slider
Display cube 3D slider in your website.
Image Parallax
image-parallax
Create images with a parallax effect. Upload some layers, configure the animation, and publish !
WP W3D plugin Developer Profile
2 plugins · 20 total installs
How We Detect WP W3D plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-w3d/assets/css/admin.css/wp-content/plugins/wp-w3d/assets/css/edit-slider.css/wp-content/plugins/wp-w3d/assets/js/edit-slider.js/wp-content/plugins/wp-w3d/assets/js/edit-slider.jswp-w3d-admin-styles?ver=wp-w3d-admin-edit-slider-styles?ver=wp-w3d-admin-edit-slider-script?ver=HTML / DOM Fingerprints
w3dslider