GA Made Simple by Devictio Security & Risk Analysis

wordpress.org/plugins/ga-made-simple

Add Google Analytics code on each page with classic or universal code

10 active installs v2.0 PHP + WP 3.3+ Updated Sep 17, 2014
e-commercegagooglegoogle-analyticswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GA Made Simple by Devictio Safe to Use in 2026?

Generally Safe

Score 85/100

GA Made Simple by Devictio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The plugin "ga-made-simple" v2.0 exhibits a generally strong security posture due to a complete lack of identified CVEs and a well-defined, albeit small, attack surface. The code signals are also promising, with 100% of SQL queries utilizing prepared statements and a single capability check indicating some level of access control. However, a significant concern arises from the output escaping analysis, where 0% of the 15 total outputs are properly escaped. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data, if not handled correctly, could be injected into the output rendered by the plugin.

The taint analysis revealed one flow with an unsanitized path, which, while not flagged as critical or high severity in this report, still warrants attention. The absence of dangerous functions, file operations, external HTTP requests, and nonce checks is positive, contributing to a reduced risk profile. The vulnerability history is clean, which is an excellent indicator of past security diligence. Despite the lack of reported vulnerabilities, the unescaped output and the single unsanitized path in the taint analysis are concrete areas for improvement that could lead to exploitable issues.

Key Concerns

  • Unescaped output detected
  • Taint flow with unsanitized path
Vulnerabilities
None known

GA Made Simple by Devictio Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GA Made Simple by Devictio Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped15 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
ga_made_simple (ga-made-simple.php:119)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GA Made Simple by Devictio Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_headga-made-simple.php:190
actionadmin_menuga-made-simple.php:194
actionwoocommerce_thankyouga-made-simple.php:280
Maintenance & Trust

GA Made Simple by Devictio Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedSep 17, 2014
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

GA Made Simple by Devictio Developer Profile

Nicolas GRILLET

3 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GA Made Simple by Devictio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ga-made-simple/ga-made-simple.php
Script Paths
//www.google-analytics.com/analytics.jshttps://stats.g.doubleclick.net/dc.jshttp://stats.g.doubleclick.net/dc.jshttps://ssl.google-analytics.com/ga.jshttp://ssl.google-analytics.com/ga.js

HTML / DOM Fingerprints

CSS Classes
tog
HTML Comments
<!-- Google Analytics Tracking with Devictio Plugin http://www.devictio.fr --><!-- WARNING : Please go to GA Made Simple settings -->
Data Attributes
name="ua_code"name="universal"name="sub_domain"name="many_domain"name="display"name="campain"+1 more
JS Globals
var author_url='http://www.devictio.fr';
FAQ

Frequently Asked Questions about GA Made Simple by Devictio