
User Tour Guide Security & Risk Analysis
wordpress.org/plugins/user-tour-guideA simple lightweight onboarding tour guide plugin. Create an unlimited number of onboarding tours for unlimited pages, work with any page builder.
Is User Tour Guide Safe to Use in 2026?
Generally Safe
Score 100/100User Tour Guide has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The user-tour-guide plugin, version 1.0.6, presents a concerning security posture primarily due to its extensive unprotected attack surface. While the plugin demonstrates good practices in areas like output escaping and SQL query preparation, the sheer number of AJAX handlers (20 out of 20) that lack authentication checks creates a significant risk. This means any unauthenticated user could potentially interact with these handlers, leading to unexpected behavior or even exploitation if vulnerabilities exist within them.
The static analysis reveals no critical or high severity issues in taint flows, and there are no recorded vulnerabilities in its history. This suggests that while the code might be susceptible to certain attacks due to the lack of authorization, actively exploitable vulnerabilities might not be present or have been fixed. The plugin also employs a good number of nonce checks, but this is undermined by the absence of capability checks on the majority of its entry points.
In conclusion, the plugin's strength lies in its code sanitization and lack of known vulnerabilities. However, the identified lack of authorization checks on its AJAX handlers is a substantial weakness that significantly elevates its risk profile. Addressing this would be crucial for improving its overall security.
Key Concerns
- AJAX handlers without auth checks
- Capability checks on entry points
User Tour Guide Security Vulnerabilities
User Tour Guide Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
User Tour Guide Attack Surface
AJAX Handlers 20
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
User Tour Guide Maintenance & Trust
Maintenance Signals
Community Trust
User Tour Guide Alternatives
Simple Tour Guide
simple-tour-guide
Easily add an interactive step-by-step user guide (intro tour) for your visitors. Based on Shepherd.js (https://shepherdjs.dev/).
Usetiful – Digital Adoption Platform
usetiful-digital-adoption-platform
Fight user churn with great user onboarding! Interactive product tours, smart tips and user onboarding checklists for digital products
Admin Tour
admin-tour
Admin Tour helps you to create a tour for admin. Admin user can go through the tour and they will get the knowledge about how to use the admin panel.
Custom Welcome Guide
custom-welcome-guide
Easily add step-by-step tours/tutorials/walkthrough guides that get displayed in the WordPress admin. Replace the default welcome guide modal dialog i …
UserGuiding
userguiding
UserGuiding is an onboarding software that helps you create quick, hassle-free, and interactive guides for an easier product journey.
User Tour Guide Developer Profile
1 plugin · 30 total installs
How We Detect User Tour Guide
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-tour-guide/admin/css/utgk-global.css/wp-content/plugins/user-tour-guide/admin/css/bootstrap.min.css/wp-content/plugins/user-tour-guide/admin/css/user-tour-guide-admin.css/wp-content/plugins/user-tour-guide/public/css/tour.min.css/wp-content/plugins/user-tour-guide/admin/css/user-tour-guide-setting.css/wp-content/plugins/user-tour-guide/admin/js/utgk-admin-script.js/wp-content/plugins/user-tour-guide/public/js/user-tour-guide-public.js/wp-content/plugins/user-tour-guide/admin/js/utgk-admin-script.js/wp-content/plugins/user-tour-guide/public/js/user-tour-guide-public.jsuser-tour-guide/admin/css/utgk-global.css?ver=user-tour-guide/admin/css/bootstrap.min.css?ver=user-tour-guide/admin/css/user-tour-guide-admin.css?ver=user-tour-guide/public/css/tour.min.css?ver=user-tour-guide/admin/css/user-tour-guide-setting.css?ver=user-tour-guide/admin/js/utgk-admin-script.js?ver=user-tour-guide/public/js/user-tour-guide-public.js?ver=HTML / DOM Fingerprints
utgk-tour-stepdata-utgk-tour-steputgk_admin_objectutgk_public_object