
GA Code Visibility Security & Risk Analysis
wordpress.org/plugins/ga-code-visibilityEasily add Google Analytics code to your head and use it only when site is switched to "Search Engine Visibility".
Is GA Code Visibility Safe to Use in 2026?
Generally Safe
Score 85/100GA Code Visibility has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of 'ga-code-visibility' v0.4 reveals a plugin with a seemingly minimal attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, and therefore no unprotected entry points. The code also avoids dangerous functions, file operations, and external HTTP requests. Furthermore, all SQL queries are confirmed to use prepared statements, which is a strong security practice.
However, a significant concern arises from the complete lack of output escaping, with 100% of identified outputs being unescaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is ever reflected directly in the output without proper sanitization. The absence of nonce checks and capability checks across all entry points is also a weakness, as it means any authenticated user could potentially trigger actions within the plugin, even if those actions were intended for administrators.
The plugin's vulnerability history is clean, with no known CVEs or past vulnerabilities. This suggests a good track record, but it does not negate the inherent risks identified in the current code. In conclusion, while the plugin demonstrates strengths in avoiding common pitfalls like raw SQL and external requests, the critical lack of output escaping and insufficient authorization checks present notable security risks.
Key Concerns
- Outputs are not properly escaped
- No nonce checks on entry points
- No capability checks on entry points
GA Code Visibility Security Vulnerabilities
GA Code Visibility Code Analysis
Output Escaping
GA Code Visibility Attack Surface
WordPress Hooks 3
Maintenance & Trust
GA Code Visibility Maintenance & Trust
Maintenance Signals
Community Trust
GA Code Visibility Alternatives
GTM Code Visibility
gtm-code-visibility
Easily add Google Tag Manager code to your site and use it only when site is switched to "Search Engine Visibility".
AddFunc Head & Footer Code
addfunc-head-footer-code
Easily add code to your head, footer and/or immediately after the opening body tag, site-wide and/or on any individual page/post.
Embed Code – Headers & Footers by DesignBombs
embed-code
The easiest way to embed code in the head or footer of your site, globally or on a per-page/post basis.
Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript
add-custom-codes
Add custom codes to your wordpress site. A completely free plugin to add Custom PHP functions, HTML, CSS, Javascript, any other codes to your website.
Vanilla Bean – Meta Maid
vanilla-bean-meta-maid
Meta Maid is the simplest of plugins, allowing you to add meta tags, script tags and tracking code to
GA Code Visibility Developer Profile
2 plugins · 60 total installs
How We Detect GA Code Visibility
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ga-code-visibility/js/ga-plugin.js/wp-content/plugins/ga-code-visibility/js/ga-plugin.js