Goal Tracker – Custom Event Tracking for GA4 Security & Risk Analysis
wordpress.org/plugins/goal-tracker-gaGoal Tracker - Custom Events Tracking for Google Analytics 4
Is Goal Tracker – Custom Event Tracking for GA4 Safe to Use in 2026?
Generally Safe
Score 92/100Goal Tracker – Custom Event Tracking for GA4 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'goal-tracker-ga' plugin version 1.1.6 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerability history, which suggests a generally well-maintained codebase. However, a significant concern arises from the static analysis, which reveals one unprotected AJAX handler. This represents a direct entry point into the plugin's functionality that is not protected by authentication or capability checks, potentially allowing unauthenticated users to trigger sensitive actions.
While the taint analysis shows no critical or high-severity flows, the lack of nonce checks on the identified AJAX handler is a critical omission. This, combined with the single unprotected entry point, creates a notable risk of Cross-Site Request Forgery (CSRF) attacks or other unauthorized actions if this AJAX endpoint performs any state-changing operations. The absence of known CVEs is a positive indicator, but it does not negate the risks presented by the uncovered attack vector in the current version. The overall security is therefore weakened by this single, albeit potentially significant, oversight.
Key Concerns
- Unprotected AJAX handler
- Missing nonce checks on AJAX handler
- Partially unescaped output
Goal Tracker – Custom Event Tracking for GA4 Security Vulnerabilities
Goal Tracker – Custom Event Tracking for GA4 Code Analysis
Bundled Libraries
Output Escaping
Goal Tracker – Custom Event Tracking for GA4 Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
Goal Tracker – Custom Event Tracking for GA4 Maintenance & Trust
Maintenance Signals
Community Trust
Goal Tracker – Custom Event Tracking for GA4 Alternatives
GTM Kit – Google Tag Manager & GA4 integration
gtm-kit
Google Tag Manager and GA4 integration. Including WooCommerce data for Google Analytics 4 and support for server side GTM.
WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics
wp-google-analytics-events
Track Google Analytics Events on your website - Enables you to send an event when a user Scrolls or Click an element on your website.
HT Easy GA4 – Google Analytics WordPress Plugin
ht-easy-google-analytics
HT Easy GA4 - Google Analytics WordPress Plugin enables tracking user behavior and viewing Google Analytics dashboard reports from your website.
Analytics Tracker
analytics-tracker
Analytics Tracker makes it super easy to add Google Analytics tracking code on your site
WP Scroll Depth
wp-scroll-depth
Add user scrolling events to your Google Analytics simply by installing this plugin.
Goal Tracker – Custom Event Tracking for GA4 Developer Profile
3 plugins · 8K total installs
How We Detect Goal Tracker – Custom Event Tracking for GA4
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/goal-tracker-ga/public/css/wp-goal-tracker-ga-public.css/wp-content/plugins/goal-tracker-ga/public/js/wp-goal-tracker-ga-public.js/wp-content/plugins/goal-tracker-ga/public/js/wp-goal-tracker-ga-public.jsgoal-tracker-ga/public/css/wp-goal-tracker-ga-public.css?ver=goal-tracker-ga/public/js/wp-goal-tracker-ga-public.js?ver=HTML / DOM Fingerprints
wp-goal-tracker-ga-settings-wrapPlugin Name: Goal TrackerDescription: Custom Event Tracking for Google Analytics GA4data-gtg-settings-pagegtg_fswp_goal_tracker_ga_public/wp-json/wp-goal-tracker-ga-setting-api/v1/settings