
WPLMS GA Security & Risk Analysis
wordpress.org/plugins/integrate-wplms-gaWPLMS GA is an integration of Google Analytics with WPLMS
Is WPLMS GA Safe to Use in 2026?
Generally Safe
Score 85/100WPLMS GA has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "integrate-wplms-ga" plugin v1.0 presents a concerning security posture due to critical weaknesses identified in the static analysis. While the plugin demonstrates good practices by avoiding dangerous functions and using prepared statements for its SQL queries, these strengths are overshadowed by significant risks in other areas. The most alarming finding is the presence of an unprotected AJAX handler, which represents a direct entry point for potential attackers. Furthermore, the complete lack of output escaping means that any data processed or displayed by the plugin is vulnerable to injection attacks, such as Cross-Site Scripting (XSS). The taint analysis also reveals flows with unsanitized paths, indicating that user-supplied data might not be properly validated or cleaned before being used, further exacerbating the XSS risk. The absence of vulnerability history suggests a lack of past issues, which could indicate either a well-developed plugin or simply a lack of public reporting. However, relying on this is risky given the current static analysis findings. In conclusion, despite some positive coding practices, the "integrate-wplms-ga" plugin v1.0 has critical security flaws that require immediate attention, particularly the unprotected AJAX handler and the pervasive output escaping issues.
Key Concerns
- Unprotected AJAX handler identified
- Outputs not properly escaped
- Taint flows with unsanitized paths
- Missing nonce checks on AJAX
- Missing capability checks
WPLMS GA Security Vulnerabilities
WPLMS GA Code Analysis
Output Escaping
Data Flow Analysis
WPLMS GA Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
WPLMS GA Maintenance & Trust
Maintenance Signals
Community Trust
WPLMS GA Alternatives
WPLMS WooCommerce Memberships
wplms-woocommerce-membership-addon
WPLMS woocommerce membership addon is an integration of WooCommerce Memberships with WPLMS Learning management system for WordPress.
Analytics Cat – Google Analytics Made Easy
analytics-cat
Analytics Cat - Google Analytics Lets You Add Your Google Analytics / Universal Analytics Tracking Code To Your Site With Ease.
WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics
wp-google-analytics-events
Track Google Analytics Events on your website - Enables you to send an event when a user Scrolls or Click an element on your website.
HT Easy GA4 – Google Analytics WordPress Plugin
ht-easy-google-analytics
HT Easy GA4 - Google Analytics WordPress Plugin enables tracking user behavior and viewing Google Analytics dashboard reports from your website.
Simple Universal Google Analytics
simple-universal-google-analytics
Enable Universal Google Analytics tracking option on your WordPress site. Add tracking code to every page with WordPress Google Analytics plugin.
WPLMS GA Developer Profile
20 plugins · 4K total installs
How We Detect WPLMS GA
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/integrate-wplms-ga/includes/js/wplms_ga.jsHTML / DOM Fingerprints
gawplms