
MomentoPress for Momento360 Security & Risk Analysis
wordpress.org/plugins/cmyee-momentopressAdd 360° VR photos and videos easily to your WordPress site using MomentoPress for Momento360.
Is MomentoPress for Momento360 Safe to Use in 2026?
Generally Safe
Score 85/100MomentoPress for Momento360 has a strong security track record. Known vulnerabilities have been patched promptly.
The cmyee-momentopress plugin version 1.0.2 exhibits a generally positive security posture based on the static analysis, with no identified dangerous functions, file operations, or external HTTP requests. Notably, all SQL queries are prepared, and output escaping appears to be correctly implemented, which are strong indicators of secure coding practices. The absence of critical or high-severity taint flows further reinforces this. However, the plugin's vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, even though it is currently patched. This past incident, while resolved, suggests a potential for XSS to be introduced, and the lack of identified nonce or capability checks on its single shortcode, which represents its entire attack surface, is a significant concern. While the current analysis shows no direct exploits, the historical XSS and the potential for unauthenticated shortcode execution warrant caution.
Key Concerns
- No capability checks on entry points
- No nonce checks on entry points
- History of medium XSS vulnerability
MomentoPress for Momento360 Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
MomentoPress for Momento360 <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MomentoPress for Momento360 Code Analysis
MomentoPress for Momento360 Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
MomentoPress for Momento360 Maintenance & Trust
Maintenance Signals
Community Trust
MomentoPress for Momento360 Alternatives
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress
wpvr
Create stunning 360 virtual tours to impress visitors and get more clients using WPVR - the easiest virtual tour creator in WordPress.
WonderPano – 360 Panorama Viewer
wonderpano
WonderPano is a plugin that enables you add interactive 360 photos to your WordPress website.
Garden Gnome Package
garden-gnome-package
Display panoramas, virtual tours or object movies created with Pano2VR and Object2VR.
QTVR Viewer
qtvr-viewer
This plugin inserts a panoramic player into a WordPress article to view a 360 panoramic picture in QTVR format (.mov)
FPP-Pano
fpp-pano
FPP-Pano enables your WordPress blog to easily display your panoramas using the Flash Panorama Player (FPP)
MomentoPress for Momento360 Developer Profile
1 plugin · 1K total installs
How We Detect MomentoPress for Momento360
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cmyee-momentopress/css/momentopress.csscmyee-momentopress/css/momentopress.css?ver=HTML / DOM Fingerprints
momentopress-containermomentopress-embed<div class="momentopress-container"><iframe class="momentopress-embed" src="