Goolytics – Simple Google Analytics Security & Risk Analysis

wordpress.org/plugins/goolytics-simple-google-analytics

A simple Google Analytics solution that works without slowing down your WordPress installation.

4K active installs v1.1.3 PHP + WP 3.0+ Updated Feb 15, 2026
analyticsdsgvogdprusercentricsweb-tracking
100
A · Safe
CVEs total1
Unpatched0
Last CVESep 6, 2022
Safety Verdict

Is Goolytics – Simple Google Analytics Safe to Use in 2026?

Generally Safe

Score 100/100

Goolytics – Simple Google Analytics has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Sep 6, 2022Updated 3mo ago
Risk Assessment

The "goolytics-simple-google-analytics" plugin v1.1.3 exhibits a mixed security posture. On the positive side, static analysis shows no identified dangerous functions, all SQL queries use prepared statements, and there are no file operations or external HTTP requests. Furthermore, the plugin has no known unpatched vulnerabilities. However, a significant concern is that 100% of the identified output points are not properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website. While the plugin has a history of one medium severity CVE related to XSS, and no currently unpatched vulnerabilities, the lack of output escaping in the current version suggests a potential for new XSS exploits. The absence of any identified attack surface entry points (AJAX, REST API, shortcodes, cron events) is a strength, but the lack of capability and nonce checks across these non-existent entry points is less relevant in this specific version's analysis. Overall, the plugin's lack of basic output sanitization presents a notable security risk that should be addressed.

Key Concerns

  • Unescaped output found
  • Past medium XSS vulnerability
Vulnerabilities
1 published

Goolytics – Simple Google Analytics Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-3132medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Goolytics – Simple Google Analytics <= 1.1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 6, 2022 Patched in 1.1.2 (504d)
Version History

Goolytics – Simple Google Analytics Release Timeline

v1.1.3Current
v1.1.2
v1.1.11 CVE
v1.1.01 CVE
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Goolytics – Simple Google Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

Goolytics – Simple Google Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_noticesgoolytics.php:81
actionadmin_noticesgoolytics.php:86
filterplugin_action_linksgoolytics.php:88
actionplugins_loadedgoolytics.php:90
actionadmin_initgoolytics.php:91
actionadmin_menugoolytics.php:92
actionwp_headgoolytics.php:95
actionadmin_print_scriptsinc\authorplugins.inc.php:24
Maintenance & Trust

Goolytics – Simple Google Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.99
Last updatedFeb 15, 2026
PHP min version
Downloads48K

Community Trust

Rating100/100
Number of ratings8
Active installs4K
Developer Profile

Goolytics – Simple Google Analytics Developer Profile

wpseek

7 plugins · 79K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
728 days
View full developer profile
Detection Fingerprints

How We Detect Goolytics – Simple Google Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/goolytics-simple-google-analytics/inc/authorplugins.inc.php/wp-content/plugins/goolytics-simple-google-analytics/inc/options.php

HTML / DOM Fingerprints

HTML Comments
<!-- Goolytics - Simple Google Analytics Begin --><!-- Goolytics - Simple Google Analytics End -->
Data Attributes
data-usercentrics
JS Globals
window.dataLayergtag
FAQ

Frequently Asked Questions about Goolytics – Simple Google Analytics