EchBay Tag Manager Security & Risk Analysis

wordpress.org/plugins/echbay-tag-manager

Control tags manager same same google tag manager. Easily setup Facebook pixel or Google Conversion tracking and add another Javascript code, CSS and …

50 active installs v1.2.2 PHP + WP 4.8+ Updated Nov 28, 2025
custom-tag-managereasy-tag-managergoogle-tag-managertag-managertags-manager
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EchBay Tag Manager Safe to Use in 2026?

Generally Safe

Score 100/100

EchBay Tag Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "echbay-tag-manager" v1.2.2 plugin exhibits a generally strong security posture based on the static analysis and vulnerability history. The absence of any recorded CVEs, unpatched vulnerabilities, or common vulnerability types is a positive indicator, suggesting a well-maintained codebase or a history of responsible development. The static analysis reveals a very limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are not protected by authentication and capability checks. This proactive approach to limiting entry points significantly reduces the plugin's susceptibility to external attacks.

However, several areas warrant attention. The analysis indicates that 100% of SQL queries are not using prepared statements, which is a significant risk for SQL injection vulnerabilities. Furthermore, there are no properly escaped outputs among the 11 outputs analyzed, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the plugin has a nonce check and a capability check, the lack of input sanitization for file operations and the absence of proper output escaping for all outputs are serious concerns that could be exploited by attackers. The limited taint analysis showing no unsanitized paths is good, but it is overshadowed by the evident lack of fundamental security practices in handling database queries and outputting data.

Key Concerns

  • SQL queries not using prepared statements
  • No properly escaped outputs
  • File operations present, potential for path traversal
Vulnerabilities
None known

EchBay Tag Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

EchBay Tag Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
11
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
6
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

0% escaped11 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
update (etm.php:115)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

EchBay Tag Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuetm.php:263
actionwp_headetm.php:269
actionwp_footeretm.php:270
Maintenance & Trust

EchBay Tag Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version
Downloads10K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

EchBay Tag Manager Developer Profile

Dao Quoc Dai

8 plugins · 2K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect EchBay Tag Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/echbay-tag-manager/admin.css/wp-content/plugins/echbay-tag-manager/admin.js/wp-content/plugins/echbay-tag-manager/top.js
Script Paths
/wp-content/plugins/echbay-tag-manager/admin.js/wp-content/plugins/echbay-tag-manager/top.js
Version Parameters
echbay-tag-manager/admin.css?v=echbay-tag-manager/admin.js?v=echbay-tag-manager/top.js

HTML / DOM Fingerprints

JS Globals
etm_arr_all_tagseb_plugin_key_optioneb_plugin_new_dataetm_body_class
FAQ

Frequently Asked Questions about EchBay Tag Manager