
Campaign URL Builder Security & Risk Analysis
wordpress.org/plugins/campaign-url-builderGenerate link for Analytics tools like Google Analytics and a short link.
Is Campaign URL Builder Safe to Use in 2026?
Mostly Safe
Score 84/100Campaign URL Builder is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved.
The "campaign-url-builder" plugin v1.8.2 presents a mixed security posture. While the static analysis reveals a limited attack surface with no exposed AJAX handlers or REST API routes without authentication, and a moderate percentage of properly escaped output, there are significant concerns regarding its database interaction and historical vulnerability patterns. The plugin performs a substantial number of SQL queries without using prepared statements, which is a major risk for SQL injection vulnerabilities. Additionally, the presence of historical medium severity Cross-Site Scripting (XSS) vulnerabilities, even though currently unpatched, suggests a pattern of input sanitization weaknesses that warrant caution.
Despite the absence of critical or high severity taint flows in the static analysis and the fact that all known CVEs are currently patched, the reliance on raw SQL and the history of XSS issues indicate potential areas for future exploitation if not addressed proactively. The plugin demonstrates good practices in controlling its attack surface, but the fundamental insecure handling of database queries is a critical weakness that cannot be overlooked. Therefore, while the immediate threat may be mitigated by current patching, the underlying code quality concerning SQL security and past XSS issues suggests a moderate to high risk for ongoing vigilance.
Key Concerns
- SQL queries without prepared statements
- History of medium severity XSS vulnerabilities
- Moderate output unescaped (30%)
Campaign URL Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Campaign URL Builder <= 1.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Campaign URL Builder <= 1.8.1 - Authenticated (Admin+) Stored Cross-Site Scripting via Create Link
Campaign URL Builder Release Timeline
Campaign URL Builder Code Analysis
SQL Query Safety
Output Escaping
Campaign URL Builder Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Campaign URL Builder Maintenance & Trust
Maintenance Signals
Community Trust
Campaign URL Builder Alternatives
utm.codes
utm-dot-codes
A WordPress plugin that makes building analytics friendly links quick and easy.
UTM Generator
tru-utm-generator
Generate UTM links
UTM Code Generator for Google Analytics Tracking URL
utm-generator
In order to make the visitors tracking easy, Google analytics created the UTM tracker, for this reason
Rakam Link Tracking
rakam-link-tracking
An Extension for WordPress that allows you to Link Tracking.
UTM – URL Builder for GA4
utm-url-builder-ga4
Add a UTM & URL builder to your site for GA4.
Campaign URL Builder Developer Profile
3 plugins · 600 total installs
How We Detect Campaign URL Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/campaign-url-builder/css/cub.css/wp-content/plugins/campaign-url-builder/js/cub.js/wp-content/plugins/campaign-url-builder/js/cub.jscampaign-url-builder/css/cub.css?ver=campaign-url-builder/js/cub.js?ver=HTML / DOM Fingerprints
cub-shortcode-outputdata-cub-form-idcub_ajax_url<div class="cub-shortcode-output">