
CBX Tour – User Walkthroughs & Guided Tours Security & Risk Analysis
wordpress.org/plugins/cbxtakeatourA plugin to create interactive feature tour/User Walkthroughs/Guided Tours for product, service or any feature demonstration
Is CBX Tour – User Walkthroughs & Guided Tours Safe to Use in 2026?
Generally Safe
Score 100/100CBX Tour – User Walkthroughs & Guided Tours has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cbxtakeatour" plugin v1.2.1 presents a mixed security posture. While the absence of known vulnerabilities in its history is a positive indicator, the static analysis reveals significant concerns regarding its attack surface. A large proportion of its entry points, specifically all six AJAX handlers, lack proper authentication checks, creating a substantial risk of unauthorized actions being performed. Although the taint analysis found no critical or high severity issues and most output is properly escaped, the unprotected AJAX endpoints could still be exploited if they perform sensitive operations or expose information. The plugin's use of prepared statements for half of its SQL queries is a good practice, but the remaining queries are not explicitly detailed and could be a source of SQL injection if not handled correctly. The presence of nonce checks on these AJAX handlers is a mitigating factor, but their absence of capability checks leaves them open to being called by unauthenticated users.
Overall, the plugin exhibits good practices in output escaping and SQL query preparation for a portion of its queries, and has a clean vulnerability history. However, the critical weakness lies in the exposure of its AJAX endpoints without sufficient authorization. This significantly increases the risk of unauthorized access and potential manipulation of plugin functionality. While the taint analysis did not uncover immediate critical flaws, the unprotected entry points are a prime target for attackers seeking to exploit any potential logic flaws or vulnerable functions within those endpoints. The plugin's strength is its lack of historical vulnerabilities, but its weakness is a substantial attack surface that is not adequately protected.
Key Concerns
- Unprotected AJAX handlers
- 50% of SQL queries not using prepared statements
- Output escaping not 100%
CBX Tour – User Walkthroughs & Guided Tours Security Vulnerabilities
CBX Tour – User Walkthroughs & Guided Tours Release Timeline
CBX Tour – User Walkthroughs & Guided Tours Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CBX Tour – User Walkthroughs & Guided Tours Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 24
Maintenance & Trust
CBX Tour – User Walkthroughs & Guided Tours Maintenance & Trust
Maintenance Signals
Community Trust
CBX Tour – User Walkthroughs & Guided Tours Alternatives
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
wp-travel-engine
WP Travel Engine is the most popular tour and travel booking WordPress plugin. Used by over 20,000 travel agency websites.
BA Book Everything
ba-book-everything
The really fast and powerful Booking engine for theme/site developers to create any booking or rental sites (tours, cars, events, apartments, yachts)
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress
wpvr
Create stunning 360 virtual tours to impress visitors and get more clients using WPVR - the easiest virtual tour creator in WordPress.
WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor
wte-elementor-widgets
WP Travel Engine – Elementor Widgets provides 20+ Elementor widgets to create travel and tour booking websites using WP Travel Engine and Elementor.
iPanorama 360 – Advanced Virtual Tour Builder
ipanorama-360-virtual-tour-builder-lite
Let's create virtual tours for your site that empowers your visitors and clients!!! Build a live tour in just a few steps.
CBX Tour – User Walkthroughs & Guided Tours Developer Profile
10 plugins · 3K total installs
How We Detect CBX Tour – User Walkthroughs & Guided Tours
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cbxtakeatour/assets/css/cbxtakeatour.css/wp-content/plugins/cbxtakeatour/assets/js/cbxtakeatour.js/wp-content/plugins/cbxtakeatour/assets/js/cbxtakeatour-admin.js/wp-content/plugins/cbxtakeatour/assets/css/cbxtakeatour-admin.css/wp-content/plugins/cbxtakeatour/assets/js/cbxtakeatour.js/wp-content/plugins/cbxtakeatour/assets/js/cbxtakeatour-admin.jscbxtakeatour/assets/css/cbxtakeatour.css?ver=cbxtakeatour/assets/js/cbxtakeatour.js?ver=cbxtakeatour/assets/js/cbxtakeatour-admin.js?ver=cbxtakeatour/assets/css/cbxtakeatour-admin.css?ver=HTML / DOM Fingerprints
cbxtakeatour-tourcbxtakeatour-stepcbxtakeatour-tooltip<!-- CBXTakeaTour Tour --><!-- CBXTakeaTour Step -->data-tour-iddata-step-iddata-tooltip-contentwindow.cbxtakeatour_settingsvar cbxtakeatour_ajax_url/wp-json/cbxtakeatour/v1/tours/wp-json/cbxtakeatour/v1/tours/(?P<id>\d+)/wp-json/cbxtakeatour/v1/steps/wp-json/cbxtakeatour/v1/steps/(?P<id>\d+)[cbxtakeatour_tour][cbxtakeatour_step]