
Goolytics – Simple Google Analytics Security & Risk Analysis
wordpress.org/plugins/goolytics-simple-google-analyticsA simple Google Analytics solution that works without slowing down your WordPress installation.
Is Goolytics – Simple Google Analytics Safe to Use in 2026?
Generally Safe
Score 100/100Goolytics – Simple Google Analytics has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "goolytics-simple-google-analytics" plugin v1.1.3 exhibits a mixed security posture. On the positive side, static analysis shows no identified dangerous functions, all SQL queries use prepared statements, and there are no file operations or external HTTP requests. Furthermore, the plugin has no known unpatched vulnerabilities. However, a significant concern is that 100% of the identified output points are not properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website. While the plugin has a history of one medium severity CVE related to XSS, and no currently unpatched vulnerabilities, the lack of output escaping in the current version suggests a potential for new XSS exploits. The absence of any identified attack surface entry points (AJAX, REST API, shortcodes, cron events) is a strength, but the lack of capability and nonce checks across these non-existent entry points is less relevant in this specific version's analysis. Overall, the plugin's lack of basic output sanitization presents a notable security risk that should be addressed.
Key Concerns
- Unescaped output found
- Past medium XSS vulnerability
Goolytics – Simple Google Analytics Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Goolytics – Simple Google Analytics <= 1.1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Goolytics – Simple Google Analytics Release Timeline
Goolytics – Simple Google Analytics Code Analysis
Output Escaping
Goolytics – Simple Google Analytics Attack Surface
WordPress Hooks 8
Maintenance & Trust
Goolytics – Simple Google Analytics Maintenance & Trust
Maintenance Signals
Community Trust
Goolytics – Simple Google Analytics Alternatives
SV Tracking Manager
sv-tracking-manager
SV Tracking Manager allows you to implement tracking scripts on your website - GDPR (DSGVO) compatible with Usercentrics support.
Google Analytics Opt-Out
google-analytics-opt-out
Provides opt-out functionality for Google Analytics.
Opt-Out for Google Analytics (DSGVO / GDPR)
opt-out-for-google-analytics
Allows the user to opt-out of Google Analytics tracking. DSGVO / GDPR.
etracker analytics
etracker
Consent-free, despite ad blockers and tracking prevention: Web analytics, tag and consent manager for best data quality, ad returns and conversions.
USERCENTRICS CMP
usercentrics-consent-management-platform
Embed the Usercentrics Consent Management Platform on your website. Just enter your personal Settings ID and you're good to go.
Goolytics – Simple Google Analytics Developer Profile
7 plugins · 79K total installs
How We Detect Goolytics – Simple Google Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/goolytics-simple-google-analytics/inc/authorplugins.inc.php/wp-content/plugins/goolytics-simple-google-analytics/inc/options.phpHTML / DOM Fingerprints
<!-- Goolytics - Simple Google Analytics Begin --><!-- Goolytics - Simple Google Analytics End -->data-usercentricswindow.dataLayergtag