Easy Panorama Security & Risk Analysis

wordpress.org/plugins/easy-panorama

Embed interactive wide/panoramic images on your site. Optimised for responsive layouts, it works great with devices equipped with motion sensors.

500 active installs v1.1.5 PHP 5.6+ WP 4.5+ Updated Jan 25, 2023
imagepanoramapanoramic-imageresponsiveshortcode
85
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 15, 2023
Safety Verdict

Is Easy Panorama Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Panorama has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 15, 2023Updated 3yr ago
Risk Assessment

The "easy-panorama" v1.1.5 plugin exhibits a generally good security posture based on the static analysis. There are no identified dangerous functions, all SQL queries use prepared statements, and a very high percentage of output is properly escaped. The plugin also avoids file operations and external HTTP requests, which reduces potential attack vectors. The absence of any identified taint flows with unsanitized paths further strengthens its security profile.

However, the plugin's vulnerability history is a significant concern. It has one known CVE, which was medium severity and related to Cross-site Scripting. While this vulnerability is currently patched, its existence indicates that the plugin is not entirely immune to security flaws. The fact that the last vulnerability was relatively recent (February 2023) suggests a pattern of potential weaknesses that may resurface or manifest in new forms.

Despite the positive static analysis results, the past medium-severity XSS vulnerability warrants caution. The lack of capability checks and nonce checks across its attack surface (even though the attack surface is reported as zero entry points) could become a concern if new functionality is added without proper security considerations. Therefore, while the current version appears to be in a good state, ongoing monitoring and potential future audits are advisable.

Key Concerns

  • Past medium severity CVE
  • 0 Nonce checks detected
  • 0 Capability checks detected
Vulnerabilities
1

Easy Panorama Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-23799medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Easy Panorama <= 1.1.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

Feb 15, 2023 Patched in 1.1.5 (342d)
Code Analysis
Analyzed Mar 16, 2026

Easy Panorama Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
53 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped57 total outputs
Attack Surface

Easy Panorama Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Easy Panorama Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJan 25, 2023
PHP min version5.6
Downloads15K

Community Trust

Rating72/100
Number of ratings5
Active installs500
Developer Profile

Easy Panorama Developer Profile

Leonardo Giacone

2 plugins · 3K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
342 days
View full developer profile
Detection Fingerprints

How We Detect Easy Panorama

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-panorama/admin/js/easy-panorama-button.js
Script Paths
/wp-content/plugins/easy-panorama/admin/js/easy-panorama-button.js
Version Parameters
easy-panorama/admin/js/easy-panorama-button.js?ver=

HTML / DOM Fingerprints

CSS Classes
insert-panorama
Data Attributes
data-editor
FAQ

Frequently Asked Questions about Easy Panorama