
Groundworx GTM – Simple Insert for Google Tag Manager Security & Risk Analysis
wordpress.org/plugins/groundworx-gtmCleanly inject Google Tag Manager (GTM) into your site using WordPress-native hooks. No tracking for selected user roles.
Is Groundworx GTM – Simple Insert for Google Tag Manager Safe to Use in 2026?
Generally Safe
Score 100/100Groundworx GTM – Simple Insert for Google Tag Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "groundworx-gtm" v1.1.0 plugin exhibits a generally good security posture with several positive indicators. The complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests suggests a well-contained and carefully developed plugin. The high percentage of properly escaped output further bolsters confidence in its ability to prevent common cross-site scripting (XSS) vulnerabilities. However, a significant concern arises from the presence of a REST API route that lacks permission callbacks. This creates a direct, unprotected entry point into the plugin's functionality, which could be exploited if the endpoint handles sensitive data or performs critical actions without proper authorization. The lack of known vulnerabilities in its history is a positive sign, but it does not negate the risks identified in the static analysis. The plugin's strengths lie in its clean code and avoidance of dangerous practices, but the single unprotected REST API endpoint is a notable weakness that warrants immediate attention.
Key Concerns
- Unprotected REST API route
Groundworx GTM – Simple Insert for Google Tag Manager Security Vulnerabilities
Groundworx GTM – Simple Insert for Google Tag Manager Release Timeline
Groundworx GTM – Simple Insert for Google Tag Manager Code Analysis
Output Escaping
Groundworx GTM – Simple Insert for Google Tag Manager Attack Surface
REST API Routes 1
WordPress Hooks 6
Maintenance & Trust
Groundworx GTM – Simple Insert for Google Tag Manager Maintenance & Trust
Maintenance Signals
Community Trust
Groundworx GTM – Simple Insert for Google Tag Manager Alternatives
Easy GTM Snippet
easy-gtm-snippet
A simple plugin to add Google Tag Manager to your WordPress site.
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
GTM Kit – Google Tag Manager & GA4 integration
gtm-kit
Google Tag Manager and GA4 integration. Including WooCommerce data for Google Analytics 4 and support for server side GTM.
WEBKINDER Integration for Google Analytics and Google Tag Manager
wk-google-analytics
Google Analytics or Google Tag Manager for WordPress without tracking your own visits.
WP Global Site Tag
wp-global-site-tag
Global Site Tag (gtag.js) is a new Google Analytics replacement – giving you better control while making implementation easier. Using gtag.
Groundworx GTM – Simple Insert for Google Tag Manager Developer Profile
4 plugins · 100 total installs
How We Detect Groundworx GTM – Simple Insert for Google Tag Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/groundworx-gtm/build/index.js/wp-content/plugins/groundworx-gtm/build/index.csshttps://www.googletagmanager.com/gtm.jsgroundworx-gtm/build/index.js?ver=groundworx-gtm/build/index.css?ver=HTML / DOM Fingerprints
<!-- GTM Head --><!-- End GTM Head --><!-- GTM Body --><!-- End GTM Body -->id="groundworx-gtm-settings"window.dataLayer/wp-json/groundworx-gtm/v1/settings