CubeLaunch Security & Risk Analysis

wordpress.org/plugins/cubelaunch

Embed interactive, rotatable, pinch and zoom 3D cubes or pyramids with custom faces via Gutenberg blocks, shortcodes, or a site-wide Coming Soon page.

10 active installs v1.0.3 PHP 7.4+ WP 5.8+ Updated Dec 2, 2025
3dblockcoming-soonshortcodewebgl
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is CubeLaunch Safe to Use in 2026?

Generally Safe

Score 100/100

CubeLaunch has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The cubelaunch v1.0.3 plugin demonstrates a strong security posture based on the provided static analysis. A significant strength is the complete absence of dangerous functions and raw SQL queries; all database interactions are handled via prepared statements. Furthermore, robust security measures are evident with a high percentage of properly escaped output and the presence of nonce and capability checks on all identified entry points, including AJAX handlers and shortcodes. The lack of file operations and external HTTP requests also minimizes common attack vectors.

The taint analysis reveals no unsanitized paths, indicating that data flowing through the plugin is handled safely. The vulnerability history being completely clear, with no recorded CVEs, further supports the notion that this plugin has been developed with security in mind and has not been a target of publicly disclosed vulnerabilities. The low attack surface, consisting of only a few AJAX handlers and shortcodes, and all of which appear to be protected, further reduces potential exposure.

Overall, cubelaunch v1.0.3 presents a very good security profile. The developers have implemented many critical security best practices, including secure database handling, output escaping, and robust authentication and authorization checks on its entry points. The absence of any known vulnerabilities or concerning code signals suggests a well-maintained and secure plugin. There are no apparent weaknesses to highlight based on this analysis, positioning it as a low-risk plugin.

Vulnerabilities
None known

CubeLaunch Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CubeLaunch Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
214 escaped
Nonce Checks
5
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped248 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
cubelaunch_get_metabox_face_fields_ajax_handler (cubelaunch.php:1792)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CubeLaunch Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 3

authwp_ajax_cubelaunch_upload_cropped_imagecubelaunch.php:1279
authwp_ajax_cubelaunch_get_face_fieldscubelaunch.php:1374
authwp_ajax_cubelaunch_get_metabox_face_fieldscubelaunch.php:1884

Shortcodes 2

[cubelaunch_canvas] cubelaunch.php:1162
[cubelaunch_shape] cubelaunch.php:2117
WordPress Hooks 21
actionwp_enqueue_scriptscubelaunch.php:173
actionwp_enqueue_scriptscubelaunch.php:236
actionwp_enqueue_scriptscubelaunch.php:248
actionadmin_enqueue_scriptscubelaunch.php:402
actionadmin_menucubelaunch.php:441
actionadmin_initcubelaunch.php:586
filtertemplate_includecubelaunch.php:1154
actioninitcubelaunch.php:1418
actionadd_meta_boxes_cubelaunch_shapecubelaunch.php:1434
actionsave_post_cubelaunch_shapecubelaunch.php:1782
filtermanage_cubelaunch_shape_posts_columnscubelaunch.php:2141
actionmanage_cubelaunch_shape_posts_custom_columncubelaunch.php:2163
filtermanage_edit-cubelaunch_shape_sortable_columnscubelaunch.php:2176
actioninitcubelaunch.php:2212
actionadmin_noticescubelaunch.php:2454
actionadmin_initcubelaunch.php:2492
actioncustomize_preview_initcubelaunch.php:2564
actionadmin_enqueue_scriptscubelaunch.php:2619
actionwp_enqueue_scriptscubelaunch.php:2696
filtercubelaunch_frontend_shared_datacubelaunch.php:2702
filterscript_loader_tagcubelaunch.php:2729
Maintenance & Trust

CubeLaunch Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version7.4
Downloads387

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

CubeLaunch Developer Profile

digibrief

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CubeLaunch

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cubelaunch/vendor/js/gl-matrix-min.js/wp-content/plugins/cubelaunch/js/cubelaunch-webgl.js
Script Paths
/wp-content/plugins/cubelaunch/vendor/js/gl-matrix-min.js/wp-content/plugins/cubelaunch/js/cubelaunch-webgl.js
Version Parameters
cubelaunch-webgl?ver=1.0.3gl-matrix-min.js?ver=2.8.1

HTML / DOM Fingerprints

CSS Classes
cubelaunch-coming-soon-activecubelaunch-titlecubelaunch-aboutcubelaunch-textcubelaunch-thankyou
Data Attributes
data-cubelaunch-instance
JS Globals
cubelaunchData
Shortcode Output
[cubelaunch_shape]
FAQ

Frequently Asked Questions about CubeLaunch