
Stape Conversion Tracking Security & Risk Analysis
wordpress.org/plugins/gtm-server-sideGoogle Tag Manager Server Side Integration Made Easy
Is Stape Conversion Tracking Safe to Use in 2026?
Generally Safe
Score 99/100Stape Conversion Tracking has a strong security track record. Known vulnerabilities have been patched promptly.
The 'gtm-server-side' v2.1.44 plugin exhibits a generally good security posture, with a strong emphasis on prepared statements for SQL queries and a high percentage of properly escaped output. The static analysis reveals no critical or high severity taint flows and a relatively small attack surface, with all identified AJAX handlers appearing to have authentication checks. However, the plugin's vulnerability history is a significant concern. Two medium severity vulnerabilities have been recorded, both related to Cross-Site Scripting (XSS), with the most recent occurring on September 27, 2024. While currently unpatched CVEs are zero, the recurring nature of XSS vulnerabilities suggests potential weaknesses in input sanitization or output encoding that may not have been fully addressed in previous fixes or could reappear in future versions. The lack of capability checks on AJAX handlers is also a potential area for improvement, although the static analysis indicates these handlers are protected by some form of authentication.
Key Concerns
- Two medium severity CVEs recorded
- No capability checks on AJAX handlers
- 83% output escaping (potential for XSS)
Stape Conversion Tracking Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
GTM Server Side <= 2.1.19 - Reflected Cross-Site Scripting
GTM Server Side <= 1.1.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Stape Conversion Tracking Code Analysis
Output Escaping
Stape Conversion Tracking Attack Surface
AJAX Handlers 3
WordPress Hooks 68
Maintenance & Trust
Stape Conversion Tracking Maintenance & Trust
Maintenance Signals
Community Trust
Stape Conversion Tracking Alternatives
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
GTM Kit – Google Tag Manager & GA4 integration
gtm-kit
Google Tag Manager and GA4 integration. Including WooCommerce data for Google Analytics 4 and support for server side GTM.
Google Analytics and Google Tag Manager
wk-google-analytics
Google Analytics or Google Tag Manager for WordPress without tracking your own visits.
WP Global Site Tag
wp-global-site-tag
Global Site Tag (gtag.js) is a new Google Analytics replacement – giving you better control while making implementation easier. Using gtag.
Tagging
tagging
AdPage Tagging is a simple to use solution for setting up Google Tag Manager Server Side.
Stape Conversion Tracking Developer Profile
1 plugin · 10K total installs
How We Detect Stape Conversion Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gtm-server-side/assets/css/frontend.css/wp-content/plugins/gtm-server-side/assets/js/frontend.js/wp-content/plugins/gtm-server-side/assets/js/gtm4wp-frontend.js/wp-content/plugins/gtm-server-side/assets/js/gtm4wp-compatibility.js/wp-content/plugins/gtm-server-side/assets/js/frontend.js/wp-content/plugins/gtm-server-side/assets/js/gtm4wp-frontend.js/wp-content/plugins/gtm-server-side/assets/js/gtm4wp-compatibility.jsgtm-server-side/assets/css/frontend.css?ver=gtm-server-side/assets/js/frontend.js?ver=gtm-server-side/assets/js/gtm4wp-frontend.js?ver=gtm-server-side/assets/js/gtm4wp-compatibility.js?ver=HTML / DOM Fingerprints
<!-- Stape Conversion Tracking --><!-- END Stape Conversion Tracking -->data-gtm_server_side_idgtm_server_side