
URL Params Security & Risk Analysis
wordpress.org/plugins/url-paramsShort Code to grab any URL parameter from the Query String and display it or display conditional content.
Is URL Params Safe to Use in 2026?
Generally Safe
Score 92/100URL Params has a strong security track record. Known vulnerabilities have been patched promptly.
The 'url-params' plugin v2.5 presents a mixed security profile. On the positive side, the static analysis indicates good practices in handling SQL queries, exclusively using prepared statements, and no file operations or external HTTP requests are detected, which reduces certain attack vectors. The absence of critical or high severity taint flows and dangerous functions is also reassuring. However, there are notable areas for concern. The plugin has a history of Cross-site Scripting (XSS) vulnerabilities, with one medium-severity CVE recorded in its past. The static analysis also reveals that 25% of output is not properly escaped, which could potentially lead to XSS if untrusted input is displayed without adequate sanitization, especially given the plugin's history. Furthermore, the lack of nonce checks and capability checks on the identified entry points (shortcodes) is a significant weakness, as it means these functions could be triggered by unauthenticated or unauthorized users. While the attack surface is small and currently lacks unprotected AJAX/REST API endpoints, the existing shortcode entry points are a clear risk.
Key Concerns
- Unescaped output detected
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Medium severity CVE in history
URL Params Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
URL Params <= 2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
URL Params Code Analysis
Output Escaping
URL Params Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
URL Params Maintenance & Trust
Maintenance Signals
Community Trust
URL Params Alternatives
Iframe plus GET Parameters
iframe-plus-get-parameters
Passes GET parameters to iframes.
WPS Hide Login
wps-hide-login
Change wp-login.php to anything you want.
Better Search Replace
better-search-replace
A simple plugin to update URLs or other text in a database.
Custom Post Type Permalinks
custom-post-type-permalinks
Edit the permalink of custom post type.
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
URL Params Developer Profile
4 plugins · 8K total installs
How We Detect URL Params
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[urlparam][ifurlparam]