
WP Tourmake Security & Risk Analysis
wordpress.org/plugins/wp-tourmakeWP Tourmake generates shortcodes that allow you to quickly and easily add your Tourmake's and Viewmake's virtual tours to your website pages …
Is WP Tourmake Safe to Use in 2026?
Generally Safe
Score 100/100WP Tourmake has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wp-tourmake" v1.0.1 presents a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and does not appear to have any publicly known vulnerabilities or unpatched CVEs. The attack surface is relatively small, with no identified AJAX handlers or REST API routes exposed without authentication, and no file operations or cron events. However, significant concerns arise from the static analysis. A substantial portion of output (83%) is not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals four high-severity flows with unsanitized paths, suggesting potential for command injection or path traversal issues, which are critical security flaws. The absence of nonce checks and capability checks, especially in conjunction with the identified taint flows and unescaped output, amplifies these risks, as these are fundamental security mechanisms to prevent unauthorized actions and data breaches. While the lack of historical vulnerabilities is a positive sign, it does not mitigate the immediate risks identified in the current code analysis.
Key Concerns
- High percentage of unescaped output
- Multiple high severity taint flows
- Missing nonce checks
- Missing capability checks
WP Tourmake Security Vulnerabilities
WP Tourmake Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Tourmake Attack Surface
Shortcodes 4
WordPress Hooks 5
Maintenance & Trust
WP Tourmake Maintenance & Trust
Maintenance Signals
Community Trust
WP Tourmake Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
WP Tourmake Developer Profile
2 plugins · 30 total installs
How We Detect WP Tourmake
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-tourmake/includes/assets/css/style.css/wp-content/plugins/wp-tourmake/includes/assets/css/admin.css/wp-content/plugins/wp-tourmake/includes/assets/tourmake-font/css/tourmake-font.css/wp-content/plugins/wp-tourmake/includes/assets/js/admin.js/wp-content/plugins/wp-tourmake/includes/assets/js/validator/validator.js/wp-content/plugins/wp-tourmake/includes/assets/js/validator/messages_it.js/wp-content/plugins/wp-tourmake/includes/assets/js/tour.jshttps://content.tourmake.it/api/tourmake-api.jswp-tourmake/includes/assets/css/style.css?ver=wp-tourmake/includes/assets/css/admin.css?ver=wp-tourmake/includes/assets/tourmake-font/css/tourmake-font.css?ver=wp-tourmake/includes/assets/js/admin.js?ver=wp-tourmake/includes/assets/js/validator/validator.js?ver=wp-tourmake/includes/assets/js/validator/messages_it.js?ver=wp-tourmake/includes/assets/js/tour.js?ver=HTML / DOM Fingerprints
wptm-tour-wrapperwptm-tour-containerwptm-vm-containerdata-iddata-localedata-fullscreendata-scrolldata-headingdata-pitch+2 moreWPTourmake<div class="wptm-tour-wrapper"><div id="wptm-tour-container" class="wptm-tour-container"<div class="wptm-vm-container"