
PanoPress Security & Risk Analysis
wordpress.org/plugins/panopressPanoPress allows easy embedding of 360° Panoramas & Virtual Tours created with KRPano, Panotour, Pano2VR & others using Flash & HTML5
Is PanoPress Safe to Use in 2026?
Generally Safe
Score 85/100PanoPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "panopress" v1.3 exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs or past vulnerabilities is a significant positive indicator, suggesting a history of stable and secure development. The plugin also demonstrates good practices in handling SQL queries, exclusively using prepared statements, and implementing nonce and capability checks for its entry points.
However, the static analysis reveals a critical concern regarding output escaping. With 0% of its 15 outputs properly escaped, the plugin is highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is directly rendered in the output without proper sanitization poses a significant risk. While the attack surface is small and appears protected, the lack of output escaping creates a substantial weak point that could be exploited.
In conclusion, while the plugin's history and foundational security practices like prepared SQL statements are commendable, the severe lack of output escaping is a major security flaw. This presents a high-risk area that requires immediate attention to prevent potential XSS attacks. The limited attack surface and absence of known vulnerabilities are strengths, but they are overshadowed by the critical vulnerability in output handling.
Key Concerns
- 0% of outputs properly escaped
- External HTTP request detected
- Bundled library (TinyMCE)
PanoPress Security Vulnerabilities
PanoPress Code Analysis
Bundled Libraries
Output Escaping
PanoPress Attack Surface
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
PanoPress Maintenance & Trust
Maintenance Signals
Community Trust
PanoPress Alternatives
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress
wpvr
Create stunning 360 virtual tours to impress visitors and get more clients using WPVR - the easiest virtual tour creator in WordPress.
iPanorama 360 – Advanced Virtual Tour Builder
ipanorama-360-virtual-tour-builder-lite
Let's create virtual tours for your site that empowers your visitors and clients!!! Build a live tour in just a few steps.
Photo Sphere Viewer – 360° Panorama, Virtual Tour & 360 Video for WordPress
photo-sphere-viewer
Display 360° panoramas, virtual tours & 360 videos on WordPress with Elementor, Gutenberg, or shortcodes. No coding needed.
360 Viewer Light
360-viewer-light-for-elementor-wpbakery
360 Photo Viewer
360 Panorama Embed
360panoembed
This plugin allows you to easily embed a panorama created using Occipital's 360 Panorama App.
PanoPress Developer Profile
1 plugin · 2K total installs
How We Detect PanoPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/panopress/css/panopress.css/wp-content/plugins/panopress/js/panopress.js/wp-content/plugins/panopress/js/panopress.min.js/wp-content/plugins/panopress/js/panopress.js/wp-content/plugins/panopress/js/panopress.min.jspanopress/css/panopress.css?ver=panopress/js/panopress.js?ver=HTML / DOM Fingerprints
panopress-viewer<!-- Panopress -->panopress[pano