
FWD Easy Virtual Tour Builder Security & Risk Analysis
wordpress.org/plugins/fwd-easy-virtual-tour-builderBuild immersive 360 virtual tours with multi-scene navigation, hotspots, camera presets, floor-map navigation, and realistic rendering.
Is FWD Easy Virtual Tour Builder Safe to Use in 2026?
Generally Safe
Score 100/100FWD Easy Virtual Tour Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The FWD Easy Virtual Tour Builder plugin, version 1.0, exhibits a mixed security posture. On the positive side, it demonstrates strong security practices by exclusively using prepared statements for SQL queries and ensuring all output is properly escaped. The absence of any known vulnerabilities, including critical or high severity ones, and no recorded history of past issues is also a significant strength, suggesting a generally well-maintained codebase. However, the plugin presents notable security concerns primarily due to its attack surface. It exposes four AJAX handlers that lack authentication checks, creating potential entry points for unauthorized actions. While taint analysis and static code signals show no direct evidence of dangerous functions or unsanitized flows in this version, the unprotected AJAX endpoints represent a significant risk that could be exploited if vulnerabilities exist within them. The lack of capability checks on these endpoints further exacerbates this risk. In conclusion, while the plugin benefits from robust SQL and output sanitization and a clean vulnerability history, the unprotected AJAX endpoints are a critical weakness that requires immediate attention. Future development should prioritize implementing proper authentication and authorization checks for all exposed AJAX handlers to mitigate potential security risks.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without capability checks
FWD Easy Virtual Tour Builder Security Vulnerabilities
FWD Easy Virtual Tour Builder Release Timeline
FWD Easy Virtual Tour Builder Code Analysis
Output Escaping
FWD Easy Virtual Tour Builder Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
FWD Easy Virtual Tour Builder Maintenance & Trust
Maintenance Signals
Community Trust
FWD Easy Virtual Tour Builder Alternatives
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress
wpvr
Create stunning 360 virtual tours to impress visitors and get more clients using WPVR - the easiest virtual tour creator in WordPress.
HappyVR – Virtual Tour Builder & 360 Panorama Viewer
happyvr
Create high-performance 360° virtual tours in minutes with a feature-rich, React-powered builder optimized for smooth editing and fast loading.
iPanorama 360 – Advanced Virtual Tour Builder
ipanorama-360-virtual-tour-builder-lite
Let's create virtual tours for your site that empowers your visitors and clients!!! Build a live tour in just a few steps.
Photo Sphere Viewer – 360° Panorama, Virtual Tour & 360 Video for WordPress
photo-sphere-viewer
Display 360° panoramas, virtual tours & 360 videos on WordPress with Elementor, Gutenberg, or shortcodes. No coding needed.
Virtual Tour Builder
virtual-tours
Transform your WordPress site with Viar.Live Virtual Tour Builder! Create immersive 360° tours, enhance engagement with interactive hotspots, and boos …
FWD Easy Virtual Tour Builder Developer Profile
8 plugins · 90 total installs
How We Detect FWD Easy Virtual Tour Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fwd-easy-virtual-tour-builder/js/fwdevtb.js/wp-content/plugins/fwd-easy-virtual-tour-builder/css/fwdevtb.css/wp-content/plugins/fwd-easy-virtual-tour-builder/js/fwdevtb.jsfwd-easy-virtual-tour-builder/js/fwdevtb.js?ver=fwd-easy-virtual-tour-builder/css/fwdevtb.css?ver=HTML / DOM Fingerprints
fwdevtb-wrapdata-fwdevtb-srcFWDEVTB[fwdevtb id=