DataLayer for GTM and Matomo Security & Risk Analysis

wordpress.org/plugins/datalayer

Add contextual information to dataLayer for GTM and MTM

70 active installs v1.0.2 PHP 7.2+ WP 6.0+ Updated Apr 16, 2025
analyticsdatalayergoogle-tag-managergtmmatomo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DataLayer for GTM and Matomo Safe to Use in 2026?

Generally Safe

Score 100/100

DataLayer for GTM and Matomo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "datalayer" plugin v1.0.2 exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface to zero. Furthermore, the code signals are all positive, with no dangerous functions, all SQL queries using prepared statements, and all output being properly escaped. The lack of file operations, external HTTP requests, nonce checks, capability checks, and bundled libraries further reinforces its secure design.

The taint analysis reveals zero flows, indicating that there are no identified pathways for untrusted data to reach sensitive functions without proper sanitization. The plugin's vulnerability history is also completely clean, with no known CVEs, past or present. This clean record, combined with the robust static analysis findings, suggests that the developers have prioritized security and followed best practices diligently.

In conclusion, "datalayer" v1.0.2 appears to be a highly secure plugin. Its minimal attack surface, secure coding practices, and lack of vulnerability history present a very low risk to WordPress installations. The only potential area for future consideration would be the absence of capability checks and nonce checks, which, while not an immediate issue given the current lack of exposed entry points, would be a crucial consideration if new entry points were to be added in future versions.

Vulnerabilities
None known

DataLayer for GTM and Matomo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

DataLayer for GTM and Matomo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

DataLayer for GTM and Matomo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_headinc\datalayer.php:21
actionwp_enqueue_scriptsinc\modules\plugin-contact-form-7.php:5
actionwp_enqueue_scriptsinc\modules\plugin-wp-forms.php:5
actionwp_enqueue_scriptsinc\modules\search.php:39
Maintenance & Trust

DataLayer for GTM and Matomo Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 16, 2025
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

DataLayer for GTM and Matomo Developer Profile

Openmost

2 plugins · 80 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DataLayer for GTM and Matomo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/datalayer/assets/js/modules/plugin-contact-form-7.min.js/wp-content/plugins/datalayer/assets/js/modules/plugin-wp-forms.min.js/wp-content/plugins/datalayer/assets/js/modules/search.min.js
Version Parameters
ver=1.0.3

HTML / DOM Fingerprints

HTML Comments
<!-- dataLayer by Openmost --><!-- End dataLayer -->
JS Globals
window.dataLayer
FAQ

Frequently Asked Questions about DataLayer for GTM and Matomo