Unbounce Landing Pages Security & Risk Analysis

wordpress.org/plugins/unbounce

Unbounce is the most powerful standalone landing page builder available.

10K active installs v1.1.4 PHP 8.0+ WP 4.1.5+ Updated Jun 2, 2025
a-b-testingab-testingcrosplit-testingunbounce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Unbounce Landing Pages Safe to Use in 2026?

Generally Safe

Score 100/100

Unbounce Landing Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "unbounce" plugin v1.1.4 exhibits a generally strong security posture with no known vulnerabilities or critical code signals. The absence of any recorded CVEs, coupled with the fact that all SQL queries utilize prepared statements, suggests a well-developed and security-conscious approach by the developers. Furthermore, the static analysis found no dangerous functions, and the number of file operations and external HTTP requests is relatively low, indicating a limited potential for certain types of attacks.

However, there are significant areas of concern. A substantial portion of the plugin's output (69%) is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is ever rendered directly to the browser without sanitization. Additionally, the taint analysis revealed four flows with unsanitized paths, which, while not classified as critical or high severity in this specific analysis, represent potential pathways for malicious data injection if not handled carefully. The complete lack of nonce checks and capability checks, especially given the absence of an attack surface in the static analysis, is puzzling and could indicate a reliance on other security mechanisms that are not immediately apparent. This, combined with the unsanitized paths in the taint analysis, warrants caution.

In conclusion, while the "unbounce" plugin v1.1.4 has commendable strengths in its SQL handling and lack of known vulnerabilities, the high rate of unescaped output and the presence of unsanitized taint flows are significant weaknesses. The absence of explicit nonce and capability checks for any potential entry points (even if currently zero) is a general best practice that is missing. These factors collectively suggest a moderate security risk, primarily due to the potential for XSS and data sanitization issues.

Key Concerns

  • Unescaped output rate is high
  • Taint flows with unsanitized paths found
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Unbounce Landing Pages Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Unbounce Landing Pages Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
61
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

31% escaped88 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
http_response_code (UBCompatibility.php:6)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Unbounce Landing Pages Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionin_admin_footertemplates\main.php:29
actionin_admin_footertemplates\main.php:40
actionadmin_footerUBWPListTable.php:140
actioninitUnbounce-Page.php:33
actionadmin_initUnbounce-Page.php:148
actionadmin_menuUnbounce-Page.php:234
actionadmin_post_set_unbounce_domainsUnbounce-Page.php:308
actionadmin_post_flush_unbounce_pagesUnbounce-Page.php:339
Maintenance & Trust

Unbounce Landing Pages Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJun 2, 2025
PHP min version8.0
Downloads417K

Community Trust

Rating64/100
Number of ratings11
Active installs10K
Developer Profile

Unbounce Landing Pages Developer Profile

Unbounce

1 plugin · 10K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Unbounce Landing Pages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/unbounce/js/rx.lite.compat.min.js/wp-content/plugins/unbounce/js/set-unbounce-domains.js/wp-content/plugins/unbounce/js/unbounce-page.js/wp-content/plugins/unbounce/js/clipboard.min.js/wp-content/plugins/unbounce/js/unbounce-diagnostics.js/wp-content/plugins/unbounce/css/unbounce-pages.css
Script Paths
/wp-content/plugins/unbounce/js/rx.lite.compat.min.js/wp-content/plugins/unbounce/js/set-unbounce-domains.js/wp-content/plugins/unbounce/js/unbounce-page.js/wp-content/plugins/unbounce/js/clipboard.min.js/wp-content/plugins/unbounce/js/unbounce-diagnostics.js
Version Parameters
unbounce/js/set-unbounce-domains.js?ver=1.1.1

HTML / DOM Fingerprints

JS Globals
window.UB_VERSION
FAQ

Frequently Asked Questions about Unbounce Landing Pages