
iPanorama 360 – Advanced Virtual Tour Builder Security & Risk Analysis
wordpress.org/plugins/ipanorama-360-virtual-tour-builder-liteLet's create virtual tours for your site that empowers your visitors and clients!!! Build a live tour in just a few steps.
Is iPanorama 360 – Advanced Virtual Tour Builder Safe to Use in 2026?
Generally Safe
Score 86/100iPanorama 360 – Advanced Virtual Tour Builder has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "ipanorama-360-virtual-tour-builder-lite" v1.9.1 presents a mixed security posture. While the static analysis shows a controlled attack surface with no unprotected entry points and a high percentage of SQL queries using prepared statements, concerns arise from the presence of dangerous functions like `unserialize` and unsanitized flows identified during taint analysis. The significant number of past CVEs, particularly high and medium severity ones involving missing authorization, SQL injection, and XSS, indicates a recurring pattern of security weaknesses in the plugin's development history. The recent vulnerability in July 2024, although now patched, reinforces the need for vigilance. Despite good practices in output escaping and nonce checks, the historical data and specific code signals suggest that the plugin may not always implement robust input validation and authorization, making it a potential target for exploitation.
Key Concerns
- Presence of dangerous function: unserialize
- Flows with unsanitized paths identified
- History of 2 high severity CVEs
- History of 4 medium severity CVEs
- Common vulnerability types: Missing Authorization
- Common vulnerability types: SQL Injection
- Common vulnerability types: Cross-site Scripting
iPanorama 360 – Advanced Virtual Tour Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
iPanorama 360 WordPress Virtual Tour Builder <= 1.8.3 - Missing Authorization
iPanorama 360 WordPress Virtual Tour Builder <= 1.8.1 - Missing Authorization
iPanorama 360 – WordPress Virtual Tour Builder <= 1.8.0 - Authenticated (Contributor+) SQL Injection via Shortcode
iPanorama 360 – WordPress Virtual Tour Builder <= 1.7.3 - Authenticated (Admin+) SQL injection
iPanorama 360 WordPress Virtual Tour Builder <= 1.6.29 - Authenticated (Contributor+) Stored Cross-Site Scripting
iPanorama 360 WordPress Virtual Tour Builder < 1.6.22 - Reflected Cross-Site Scripting
iPanorama 360 – Advanced Virtual Tour Builder Release Timeline
iPanorama 360 – Advanced Virtual Tour Builder Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
iPanorama 360 – Advanced Virtual Tour Builder Attack Surface
REST API Routes 2
WordPress Hooks 15
Maintenance & Trust
iPanorama 360 – Advanced Virtual Tour Builder Maintenance & Trust
Maintenance Signals
Community Trust
iPanorama 360 – Advanced Virtual Tour Builder Alternatives
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress
wpvr
Create stunning 360 virtual tours to impress visitors and get more clients using WPVR - the easiest virtual tour creator in WordPress.
Photo Sphere Viewer – 360° Panorama, Virtual Tour & 360 Video for WordPress
photo-sphere-viewer
Display 360° panoramas, virtual tours & 360 videos on WordPress with Elementor, Gutenberg, or shortcodes. No coding needed.
HappyVR – Virtual Tour Builder & 360 Panorama Viewer
happyvr
Create high-performance 360° virtual tours in minutes with a feature-rich, React-powered builder optimized for smooth editing and fast loading.
FWD Easy Virtual Tour Builder
fwd-easy-virtual-tour-builder
Build immersive 360 virtual tours with multi-scene navigation, hotspots, camera presets, floor-map navigation, and realistic rendering.
360 Viewer Light
360-viewer-light-for-elementor-wpbakery
360 Photo Viewer
iPanorama 360 – Advanced Virtual Tour Builder Developer Profile
7 plugins · 11K total installs
How We Detect iPanorama 360 – Advanced Virtual Tour Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ipanorama-360-virtual-tour-builder-lite/assets/css/preview.min.css/wp-content/plugins/ipanorama-360-virtual-tour-builder-lite/assets/js/loader.min.js/wp-content/plugins/ipanorama-360-virtual-tour-builder-lite/assets/js/loader.min.jsipanorama-360-virtual-tour-builder-lite/assets/css/preview.min.css?ver=ipanorama-360-virtual-tour-builder-lite/assets/js/loader.min.js?ver=HTML / DOM Fingerprints
ipanorama-container<!-- iPanorama 360 Virtual Tour Builder --><!-- iPanorama 360 Virtual Tour Builder Lite -->data-virtualtouridipanorama_globals/wp-json/ipanorama/v1/get-tour-data[ipano