
GoToViaR Security & Risk Analysis
wordpress.org/plugins/gotoviarGOTOVIAR is an innovative plugin for WordPress sites that enables users to transform their website into an immersive Virtual Reality (VR) experience.
Is GoToViaR Safe to Use in 2026?
Generally Safe
Score 92/100GoToViaR has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gotoviar" v1.2.2 plugin exhibits a concerning security posture due to a significant lack of authorization checks on its exposed entry points. While the static analysis shows no dangerous functions, raw SQL queries, or file operations, the presence of 3 unprotected REST API routes represents a substantial risk. These routes are directly accessible and can potentially be exploited by unauthenticated users, leading to various vulnerabilities depending on their implementation. The absence of nonce and capability checks further exacerbates this risk by allowing any user to trigger these functions.
The plugin also demonstrates a critical weakness in output escaping, with 0% of its 8 output points being properly escaped. This means that sensitive data, if processed by these routes, could be susceptible to cross-site scripting (XSS) attacks. Despite the absence of recorded CVEs and taint analysis indicating no apparent issues, the identified weaknesses in authorization and output sanitization are severe enough to warrant significant caution. The plugin's vulnerability history is clean, which is a positive sign, but this does not negate the current, demonstrable risks present in the code.
Key Concerns
- REST API routes without permission callbacks
- Outputs not properly escaped
- No nonce checks
- No capability checks
GoToViaR Security Vulnerabilities
GoToViaR Code Analysis
Output Escaping
GoToViaR Attack Surface
REST API Routes 3
WordPress Hooks 4
Maintenance & Trust
GoToViaR Maintenance & Trust
Maintenance Signals
Community Trust
GoToViaR Alternatives
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress
wpvr
Create stunning 360 virtual tours to impress visitors and get more clients using WPVR - the easiest virtual tour creator in WordPress.
MomentoPress for Momento360
cmyee-momentopress
Add 360° VR photos and videos easily to your WordPress site using MomentoPress for Momento360.
Plato Gallery – Quick and Easy for VR, AR, and Metaverse Galleries
plato-gallery
Effortlessly create stunning VR, AR, and Metaverse galleries with plato.gallery for WordPress. Customize, integrate, and engage your audience!
Material3d
material3d
Material3d is a platform provides a WYSIWYG way to construct and run interactive 3d scenes on web browsers with VR (Virtual Reality) device support.
Virtual Shop For Woocommecre
virtual-shop-for-woocommecre
This plugin will connect woocommerce with vrshop. providing product information and cart processing. Payment is made on the website.
GoToViaR Developer Profile
1 plugin · 10 total installs
How We Detect GoToViaR
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gotoviar/assets/css/vendors/bootstrap.min.css/wp-content/plugins/gotoviar/assets/js/vendors/bootstrap.bundle.min.js/wp-content/plugins/gotoviar/assets/js/app.jsgotoviar/assets/css/vendors/bootstrap.min.css?ver=gotoviar/assets/js/vendors/bootstrap.bundle.min.js?ver=gotoviar/assets/js/app.js?ver=HTML / DOM Fingerprints
<!-- This file is part of the "gotoviar" project. --><!-- See "LICENSE" for license information. -->window.GTVR_AJAX_URLwindow.GTVR_NONCE/wp-json/gotoviar/system_name/wp-json/gotoviar/v1/items_count_in_cart/wp-json/gotoviar/v1/products