
Attribution Query String Manager Security & Risk Analysis
wordpress.org/plugins/attribution-query-string-managerThis plugin will help manage query string variables to ensure that desired variables are always included on certain domains.
Is Attribution Query String Manager Safe to Use in 2026?
Generally Safe
Score 85/100Attribution Query String Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "attribution-query-string-manager" plugin v0.1.3 demonstrates a generally good security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant strength, minimizing the potential attack surface. The code also utilizes prepared statements for all its SQL queries and includes nonce and capability checks, indicating adherence to basic WordPress security best practices. Furthermore, the plugin has no recorded vulnerability history, which is positive, suggesting a history of responsible development or limited exposure.
However, there are areas for concern. The most notable is the output escaping, with only 47% of outputs being properly escaped. This leaves a considerable portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks. While the taint analysis shows no critical or high-severity flows, the lack of comprehensive taint analysis (0 flows analyzed) means this assessment is not exhaustive. The presence of file operations without specific details on their nature also warrants caution. Overall, the plugin is in a relatively secure state due to its limited attack surface and use of prepared statements, but the significant percentage of unescaped output presents a tangible risk that should be addressed.
Key Concerns
- Insufficient output escaping
Attribution Query String Manager Security Vulnerabilities
Attribution Query String Manager Code Analysis
SQL Query Safety
Output Escaping
Attribution Query String Manager Attack Surface
WordPress Hooks 8
Maintenance & Trust
Attribution Query String Manager Maintenance & Trust
Maintenance Signals
Community Trust
Attribution Query String Manager Alternatives
RaraTheme Companion
raratheme-companion
23 extremely useful custom widgets to create an engaging website.
Simple Post Type Permalinks
simple-post-type-permalinks
Easy to change Permalink of custom post type.
No External Links
mihdan-no-external-links
Convert external links into internal links, site wide or post/page specific. Add NoFollow, Click logging, and more...
Admin Collapse Subpages
admin-collapse-subpages
Using this plugin one can easily collapse/expand pages with children and grand children.
Custom Post Type Rewrite
custom-post-type-rewrite
Custom Post Type Rewrite plugin adds default custom post type permalinks.
Attribution Query String Manager Developer Profile
5 plugins · 1K total installs
How We Detect Attribution Query String Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/attribution-query-string-manager/AQSM-admin.css/wp-content/plugins/attribution-query-string-manager/AQSM-admin.jsattribution-query-string-manager/AQSM-admin.css?ver=attribution-query-string-manager/AQSM-admin.js?ver=HTML / DOM Fingerprints
aqsm-post-field-labelaqsm-inner_custom_box_nonce