
Campaign URL Builder Security & Risk Analysis
wordpress.org/plugins/campaign-url-builderGenerate link for Analytics tools like Google Analytics and a short link.
Is Campaign URL Builder Safe to Use in 2026?
Mostly Safe
Score 84/100Campaign URL Builder is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The "campaign-url-builder" plugin v1.8.2 presents a mixed security posture. While the static analysis reveals a limited attack surface with no exposed AJAX handlers or REST API routes without authentication, and a moderate percentage of properly escaped output, there are significant concerns regarding its database interaction and historical vulnerability patterns. The plugin performs a substantial number of SQL queries without using prepared statements, which is a major risk for SQL injection vulnerabilities. Additionally, the presence of historical medium severity Cross-Site Scripting (XSS) vulnerabilities, even though currently unpatched, suggests a pattern of input sanitization weaknesses that warrant caution.
Despite the absence of critical or high severity taint flows in the static analysis and the fact that all known CVEs are currently patched, the reliance on raw SQL and the history of XSS issues indicate potential areas for future exploitation if not addressed proactively. The plugin demonstrates good practices in controlling its attack surface, but the fundamental insecure handling of database queries is a critical weakness that cannot be overlooked. Therefore, while the immediate threat may be mitigated by current patching, the underlying code quality concerning SQL security and past XSS issues suggests a moderate to high risk for ongoing vigilance.
Key Concerns
- SQL queries without prepared statements
- History of medium severity XSS vulnerabilities
- Moderate output unescaped (30%)
Campaign URL Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Campaign URL Builder <= 1.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Campaign URL Builder <= 1.8.1 - Authenticated (Admin+) Stored Cross-Site Scripting via Create Link
Campaign URL Builder Code Analysis
SQL Query Safety
Output Escaping
Campaign URL Builder Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Campaign URL Builder Maintenance & Trust
Maintenance Signals
Community Trust
Campaign URL Builder Alternatives
utm.codes
utm-dot-codes
A WordPress plugin that makes building analytics friendly links quick and easy.
UTM Code Generator for Google Analytics Tracking URL
utm-generator
In order to make the visitors tracking easy, Google analytics created the UTM tracker, for this reason
UTM – URL Builder for GA4
utm-url-builder-ga4
Add a UTM & URL builder to your site for GA4.
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
Campaign URL Builder Developer Profile
3 plugins · 600 total installs
How We Detect Campaign URL Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/campaign-url-builder/css/cub.css/wp-content/plugins/campaign-url-builder/js/cub.js/wp-content/plugins/campaign-url-builder/js/cub.jscampaign-url-builder/css/cub.css?ver=campaign-url-builder/js/cub.js?ver=HTML / DOM Fingerprints
cub-shortcode-outputdata-cub-form-idcub_ajax_url<div class="cub-shortcode-output">