ACh Tag Manager Security & Risk Analysis

wordpress.org/plugins/ach-tag-manager

Manage GA4 Measurement ID, Google Tag Manager, and Google Analytics. You can set up Google Analytics 4 property (GA4).

10 active installs v1.0.1 PHP 5.6+ WP 4.6+ Updated Aug 9, 2024
ga4global-site-taggoogle-analyticsgoogle-tag-managermeasurement-id
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ACh Tag Manager Safe to Use in 2026?

Generally Safe

Score 92/100

ACh Tag Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'ach-tag-manager' plugin v1.0.1 exhibits a generally strong security posture based on the static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events contributing to the attack surface is a significant positive, indicating limited entry points for attackers. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and incorporating both nonce and capability checks, which are crucial for preventing common web vulnerabilities. The clean taint analysis results, with no critical or high severity flows with unsanitized paths, further bolster this assessment.

However, a notable area for concern is the low percentage of properly escaped output. With only 21% of the 14 total outputs being properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This could allow attackers to inject malicious scripts into the website through user-provided data that is later displayed without adequate sanitization. While the plugin has no known CVEs and a clean vulnerability history, this lack of historical data might also indicate a lack of rigorous security auditing or that the plugin has not been widely deployed or tested under adversarial conditions. Therefore, while the current analysis indicates a good foundation, the output escaping deficiency represents a tangible and significant risk that needs immediate attention.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

ACh Tag Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ACh Tag Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
3 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

21% escaped14 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
achtm_option_page (includes\achtm-settings.php:9)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ACh Tag Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_enqueue_scriptsAChTM.php:36
actionadmin_noticesAChTM.php:71
filterplugin_row_metaAChTM.php:92
actionplugins_loadedAChTM.php:100
actionadmin_menuAChTM.php:106
actionwp_headincludes\ga-tagmanager\ga-tagmanager.php:11
actionwp_headincludes\ga-tagmanager\ga-tagmanager.php:40
actionwp_headincludes\ga-tagmanager\ga-tagmanager.php:69
actionwp_body_openincludes\ga-tagmanager\ga-tagmanager.php:70
Maintenance & Trust

ACh Tag Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 9, 2024
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ACh Tag Manager Developer Profile

ACh

3 plugins · 110 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ACh Tag Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ach-tag-manager/assets/css/style.css/wp-content/plugins/ach-tag-manager/assets/js/jquery-achtmTabs.js
Script Paths
https://www.googletagmanager.com/gtag/jshttps://www.googletagmanager.com/gtm.js
Version Parameters
ach-tag-manager/assets/css/style.css?ver=ach-tag-manager/assets/js/jquery-achtmTabs.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Global site tag code generated with ACh Tag Manager plugin --><!-- / Global site tag (gtag.js) - Google Analytics --><!-- Google Tag Manager code generated with ACh Tag Manager plugin --><!-- / Google Tag Manager -->+2 more
JS Globals
window.dataLayergtag
FAQ

Frequently Asked Questions about ACh Tag Manager