
UTM – URL Builder for GA4 Security & Risk Analysis
wordpress.org/plugins/utm-url-builder-ga4Add a UTM & URL builder to your site for GA4.
Is UTM – URL Builder for GA4 Safe to Use in 2026?
Generally Safe
Score 85/100UTM – URL Builder for GA4 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'utm-url-builder-ga4' plugin version 1.0.0 exhibits a generally strong security posture based on the provided static analysis. It has no known vulnerabilities in its history and demonstrates good practices by not utilizing dangerous functions, all SQL queries are prepared, and there are no file operations or external HTTP requests. The absence of any critical or high severity taint flows further bolsters this positive assessment. However, a significant concern arises from the lack of output escaping for all identified outputs. While the attack surface is small and consists of only one shortcode, and there are no unauthenticated entry points, the 100% unescaped output presents a potential Cross-Site Scripting (XSS) risk if user-supplied data is incorporated into plugin output. The complete absence of nonce checks and capability checks, while less critical in this instance due to the limited attack surface and no authentication bypass concerns identified, are generally considered weaker security practices and could become problematic if the plugin's functionality or entry points were to expand in the future.
Key Concerns
- All identified outputs are unescaped
- No nonce checks
- No capability checks
UTM – URL Builder for GA4 Security Vulnerabilities
UTM – URL Builder for GA4 Code Analysis
Output Escaping
UTM – URL Builder for GA4 Attack Surface
Shortcodes 1
Maintenance & Trust
UTM – URL Builder for GA4 Maintenance & Trust
Maintenance Signals
Community Trust
UTM – URL Builder for GA4 Alternatives
UTM – URL Builder for GA4 Developer Profile
1 plugin · 0 total installs
How We Detect UTM – URL Builder for GA4
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
ga4-url-generatorutmga4_of-fieldutmga4_of-field labelutmga4_of-field inpututmga4_of-field selectutmga4_of-output textareautmga4_regex_rulesutmga4_of-field input+5 moreutmga4_of-cp_urlutmga4_utmga4_of-cp_urlutmga4_of-url-copieddata-source_placeholderdata-source_ruledata-medium_placeholder+4 moreutmga4_copyToClipboardutmga4_textAreautmga4_successfulutmga4_msgutmga4_currObjutmga4_channel+1 more[add_ga4_utm_builder]