Lightweight Google Analytics Security & Risk Analysis

wordpress.org/plugins/lightweight-google-analytics

Easily integrate Google Analytics with WordPress using just your tracking ID.

400 active installs v1.5.0 PHP 7.0+ WP 5.0+ Updated Jan 18, 2026
analyticsconsent-modega4gdprgoogle-analytics
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lightweight Google Analytics Safe to Use in 2026?

Generally Safe

Score 100/100

Lightweight Google Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "lightweight-google-analytics" v1.5.0 plugin exhibits a generally good security posture based on the provided static analysis. The plugin demonstrates a lack of critical attack vectors such as AJAX handlers, REST API routes, or shortcodes that could be exploited without proper authentication. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests, along with the consistent use of prepared statements for all SQL queries, are strong indicators of secure coding practices. The plugin also correctly enforces capability checks for its single observed entry point. The vulnerability history also shows a clean slate, with no recorded CVEs, which is a positive sign for the plugin's overall security track record.

However, there is a notable concern regarding output escaping. With 35 total outputs, only 14% are properly escaped. This means a significant portion of the plugin's output could be susceptible to Cross-Site Scripting (XSS) attacks, especially if user-controlled data is incorporated into these outputs without adequate sanitization. While the plugin has a small attack surface and a clean history, this unescaped output represents a tangible risk that attackers could leverage. The lack of taint analysis data and nonce checks on entry points, while potentially due to a very small attack surface, also leaves room for improvement in defense-in-depth strategies.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Lightweight Google Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Lightweight Google Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
30
5 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

14% escaped35 total outputs
Attack Surface

Lightweight Google Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menulightweight-google-analytics.php:22
actionadmin_initlightweight-google-analytics.php:23
actionadmin_noticeslightweight-google-analytics.php:28
actionadmin_noticeslightweight-google-analytics.php:30
Maintenance & Trust

Lightweight Google Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 18, 2026
PHP min version7.0
Downloads8K

Community Trust

Rating100/100
Number of ratings2
Active installs400
Developer Profile

Lightweight Google Analytics Developer Profile

Andy Feliciotti

5 plugins · 15K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
110 days
View full developer profile
Detection Fingerprints

How We Detect Lightweight Google Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lightweight-google-analytics/css/style.css/wp-content/plugins/lightweight-google-analytics/js/script.js
Script Paths
/wp-content/plugins/lightweight-google-analytics/js/script.js
Version Parameters
lightweight-google-analytics/css/style.css?ver=lightweight-google-analytics/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
disable-display-featuresanonymize-ip
FAQ

Frequently Asked Questions about Lightweight Google Analytics