Groundworx GTM – Simple Insert for Google Tag Manager Security & Risk Analysis

wordpress.org/plugins/groundworx-gtm

Cleanly inject Google Tag Manager (GTM) into your site using WordPress-native hooks. No tracking for selected user roles.

10 active installs v1.1.0 PHP 7.4+ WP 5.2+ Updated Apr 1, 2026
analyticsgoogle-tag-managergtmtracking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Groundworx GTM – Simple Insert for Google Tag Manager Safe to Use in 2026?

Generally Safe

Score 100/100

Groundworx GTM – Simple Insert for Google Tag Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "groundworx-gtm" v1.1.0 plugin exhibits a generally good security posture with several positive indicators. The complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests suggests a well-contained and carefully developed plugin. The high percentage of properly escaped output further bolsters confidence in its ability to prevent common cross-site scripting (XSS) vulnerabilities. However, a significant concern arises from the presence of a REST API route that lacks permission callbacks. This creates a direct, unprotected entry point into the plugin's functionality, which could be exploited if the endpoint handles sensitive data or performs critical actions without proper authorization. The lack of known vulnerabilities in its history is a positive sign, but it does not negate the risks identified in the static analysis. The plugin's strengths lie in its clean code and avoidance of dangerous practices, but the single unprotected REST API endpoint is a notable weakness that warrants immediate attention.

Key Concerns

  • Unprotected REST API route
Vulnerabilities
None known

Groundworx GTM – Simple Insert for Google Tag Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Groundworx GTM – Simple Insert for Google Tag Manager Release Timeline

v1.1.0Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Groundworx GTM – Simple Insert for Google Tag Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
6 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped7 total outputs
Attack Surface
1 unprotected

Groundworx GTM – Simple Insert for Google Tag Manager Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/groundworx-gtm/v1/settingsgroundworx-gtm.php:126
WordPress Hooks 6
actionadmin_menugroundworx-gtm.php:30
actionadmin_enqueue_scriptsgroundworx-gtm.php:31
actionrest_api_initgroundworx-gtm.php:32
actionadmin_noticesgroundworx-gtm.php:33
actionwp_headgroundworx-gtm.php:34
actionwp_body_opengroundworx-gtm.php:35
Maintenance & Trust

Groundworx GTM – Simple Insert for Google Tag Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 1, 2026
PHP min version7.4
Downloads329

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Groundworx GTM – Simple Insert for Google Tag Manager Developer Profile

Groundworx

4 plugins · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Groundworx GTM – Simple Insert for Google Tag Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/groundworx-gtm/build/index.js/wp-content/plugins/groundworx-gtm/build/index.css
Script Paths
https://www.googletagmanager.com/gtm.js
Version Parameters
groundworx-gtm/build/index.js?ver=groundworx-gtm/build/index.css?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- GTM Head --><!-- End GTM Head --><!-- GTM Body --><!-- End GTM Body -->
Data Attributes
id="groundworx-gtm-settings"
JS Globals
window.dataLayer
REST Endpoints
/wp-json/groundworx-gtm/v1/settings
FAQ

Frequently Asked Questions about Groundworx GTM – Simple Insert for Google Tag Manager