WP Goal Tracker – Goal Tracking for Plausible Analytics Security & Risk Analysis

wordpress.org/plugins/goal-tracker

WP Goal Tracker - Goal Tracking for Plausible Analytics

50 active installs v1.0.1 PHP 5.6.20+ WP 5.5+ Updated Jun 27, 2022
analyticseventsgoalsplausible
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Goal Tracker – Goal Tracking for Plausible Analytics Safe to Use in 2026?

Generally Safe

Score 85/100

WP Goal Tracker – Goal Tracking for Plausible Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

Based on the static analysis, the "goal-tracker" plugin v1.0.1 exhibits a strong security posture with no identified entry points that are unprotected. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is highly commendable. The plugin also demonstrates good practices by utilizing capability checks and ensuring that all SQL queries are prepared.

However, a notable concern is the relatively low percentage of properly escaped outputs (57%). This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. The lack of any identified taint flows is positive, suggesting that the existing code pathways do not appear to be immediately vulnerable to injection attacks.

The vulnerability history being completely clean (0 CVEs) suggests a history of secure development or diligent patching. Overall, the plugin has several strengths, particularly in its limited attack surface and use of prepared statements. The primary area for improvement lies in ensuring all output is consistently and properly escaped.

Key Concerns

  • Unescaped output
Vulnerabilities
None known

WP Goal Tracker – Goal Tracking for Plausible Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Goal Tracker – Goal Tracking for Plausible Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
4 escaped
Nonce Checks
0
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

57% escaped7 total outputs
Attack Surface

WP Goal Tracker – Goal Tracking for Plausible Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedincludes\class-wp-goal-tracker.php:145
actionadmin_menuincludes\class-wp-goal-tracker.php:186
actionadmin_enqueue_scriptsincludes\class-wp-goal-tracker.php:187
actionrest_api_initincludes\class-wp-goal-tracker.php:189
actiongt_resgister_post_typesincludes\class-wp-goal-tracker.php:191
actionwp_enqueue_scriptsincludes\class-wp-goal-tracker.php:206
actionwp_enqueue_scriptsincludes\class-wp-goal-tracker.php:207
actionwp_headincludes\class-wp-goal-tracker.php:208
Maintenance & Trust

WP Goal Tracker – Goal Tracking for Plausible Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 27, 2022
PHP min version5.6.20
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

WP Goal Tracker – Goal Tracking for Plausible Analytics Developer Profile

yuvalo

3 plugins · 8K total installs

85
trust score
Avg Security Score
79/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect WP Goal Tracker – Goal Tracking for Plausible Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/goal-tracker/admin/css/wp-goal-tracker-admin.css/wp-content/plugins/goal-tracker/admin/js/wp-goal-tracker-admin.js/wp-content/plugins/goal-tracker/public/css/wp-goal-tracker-public.css/wp-content/plugins/goal-tracker/public/js/wp-goal-tracker-public.js
Script Paths
/wp-content/plugins/goal-tracker/admin/js/wp-goal-tracker-admin.js/wp-content/plugins/goal-tracker/public/js/wp-goal-tracker-public.js
Version Parameters
wp-goal-tracker/admin/css/wp-goal-tracker-admin.css?ver=wp-goal-tracker/admin/js/wp-goal-tracker-admin.js?ver=wp-goal-tracker/public/css/wp-goal-tracker-public.css?ver=wp-goal-tracker/public/js/wp-goal-tracker-public.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="wp-goal-tracker"
REST Endpoints
/wp-json/wp-goal-tracker-setting-api/v1/
FAQ

Frequently Asked Questions about WP Goal Tracker – Goal Tracking for Plausible Analytics