
DataLayer for GTM and Matomo Security & Risk Analysis
wordpress.org/plugins/datalayerAdd contextual information to dataLayer for GTM and MTM
Is DataLayer for GTM and Matomo Safe to Use in 2026?
Generally Safe
Score 100/100DataLayer for GTM and Matomo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "datalayer" plugin v1.0.2 exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface to zero. Furthermore, the code signals are all positive, with no dangerous functions, all SQL queries using prepared statements, and all output being properly escaped. The lack of file operations, external HTTP requests, nonce checks, capability checks, and bundled libraries further reinforces its secure design.
The taint analysis reveals zero flows, indicating that there are no identified pathways for untrusted data to reach sensitive functions without proper sanitization. The plugin's vulnerability history is also completely clean, with no known CVEs, past or present. This clean record, combined with the robust static analysis findings, suggests that the developers have prioritized security and followed best practices diligently.
In conclusion, "datalayer" v1.0.2 appears to be a highly secure plugin. Its minimal attack surface, secure coding practices, and lack of vulnerability history present a very low risk to WordPress installations. The only potential area for future consideration would be the absence of capability checks and nonce checks, which, while not an immediate issue given the current lack of exposed entry points, would be a crucial consideration if new entry points were to be added in future versions.
DataLayer for GTM and Matomo Security Vulnerabilities
DataLayer for GTM and Matomo Code Analysis
Output Escaping
DataLayer for GTM and Matomo Attack Surface
WordPress Hooks 4
Maintenance & Trust
DataLayer for GTM and Matomo Maintenance & Trust
Maintenance Signals
Community Trust
DataLayer for GTM and Matomo Alternatives
GTM4Publishers – Smart content tracking for blogs, news sites and magazines
gtm4publishers
Integrate Google Tag Manager into WordPress and generate an advanced, customizable dataLayer for publishers, blogs, and digital media.
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
GTM Kit – Google Tag Manager & GA4 integration
gtm-kit
Google Tag Manager and GA4 integration. Including WooCommerce data for Google Analytics 4 and support for server side GTM.
Event Tracking for Gravity Forms
gravity-forms-google-analytics-event-tracking
Easily add event tracking using Gravity Forms and your Google Analytics or Google Tag Manager account. Supports Google Analytics v3 and Gravity Forms …
Controls for Contact Form 7 (Redirects, Analytics & Tracking)
contact-form-7-extras
Analytics, tracking, redirects and storage for Contact Form 7.
DataLayer for GTM and Matomo Developer Profile
2 plugins · 80 total installs
How We Detect DataLayer for GTM and Matomo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/datalayer/assets/js/modules/plugin-contact-form-7.min.js/wp-content/plugins/datalayer/assets/js/modules/plugin-wp-forms.min.js/wp-content/plugins/datalayer/assets/js/modules/search.min.jsver=1.0.3HTML / DOM Fingerprints
<!-- dataLayer by Openmost --><!-- End dataLayer -->window.dataLayer