Logic Hop Google Analytics Add-on Security & Risk Analysis

wordpress.org/plugins/logic-hop-google-analytics-add-on

Add powerful Event Tracking to WordPress with the Logic Hop Google Analytics Add-on.

10 active installs v3.1.5 PHP + WP 5.0+ Updated Feb 15, 2022
google-analyticslogic-hoppersonalizationpersonalized-contentpersonalized-marketing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Logic Hop Google Analytics Add-on Safe to Use in 2026?

Generally Safe

Score 85/100

Logic Hop Google Analytics Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The static analysis of the 'logic-hop-google-analytics-add-on' v3.1.5 plugin indicates a generally strong security posture. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface. The code also demonstrates good practices with a complete absence of dangerous functions, SQL queries utilizing prepared statements, and properly escaped output. File operations are also not present, and external HTTP requests are handled as a single signal, which is manageable.

However, there are a couple of areas for concern. The taint analysis revealed two flows with unsanitized paths, and while classified as low severity, this warrants investigation to ensure no unintended data exposure or manipulation is possible. Furthermore, the complete lack of nonce checks and capability checks is a significant weakness. While the attack surface is currently zero, any future addition of entry points without these fundamental security mechanisms would immediately expose the plugin to critical vulnerabilities like Cross-Site Request Forgery (CSRF).

The plugin has a clean vulnerability history with no recorded CVEs. This, combined with the strong coding practices observed in the static analysis, suggests the developers prioritize security. However, the absence of nonce and capability checks remains a notable gap that could be addressed to further harden the plugin's security, especially if the attack surface were to expand in future versions.

Key Concerns

  • Flows with unsanitized paths found
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Logic Hop Google Analytics Add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Logic Hop Google Analytics Add-on Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped16 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
track_event (includes\google_analytics.php:205)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Logic Hop Google Analytics Add-on Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_noticeslogichop_google_analytics.php:17
actionlogichop_admin_noticelogichop_google_analytics.php:75
actionlogichop_integration_initlogichop_google_analytics.php:104
filterlogichop_check_track_eventlogichop_google_analytics.php:118
filterlogichop_client_meta_integrationslogichop_google_analytics.php:131
filterlogichop_settings_registerlogichop_google_analytics.php:157
filterlogichop_settings_validatelogichop_google_analytics.php:176
actionlogichop_configure_metaboxeslogichop_google_analytics.php:195
actionlogichop_event_savelogichop_google_analytics.php:224
actionwp_headlogichop_google_analytics.php:252
actionlogichop_admin_enqueue_styleslogichop_google_analytics.php:267
actionlogichop_admin_enqueue_scriptslogichop_google_analytics.php:282
Maintenance & Trust

Logic Hop Google Analytics Add-on Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedFeb 15, 2022
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Logic Hop Google Analytics Add-on Developer Profile

Logic Hop

12 plugins · 190 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Logic Hop Google Analytics Add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/logic-hop-google-analytics-add-on/css/google-analytics.css/wp-content/plugins/logic-hop-google-analytics-add-on/js/google-analytics.js
Script Paths
https://www.googletagmanager.com/gtag/js?id=UA-82648131-1
Version Parameters
logic-hop-google-analytics-add-on/css/google-analytics.css?ver=logic-hop-google-analytics-add-on/js/google-analytics.js?ver=

HTML / DOM Fingerprints

CSS Classes
logichop-goal-google-event
HTML Comments
<!-- Global site tag (gtag.js) - Google Analytics -->
Data Attributes
data-logichop-ga-titledata-logichop-ga-pagedata-logichop-ga-hitdata-logichop-ga-ecdata-logichop-ga-eadata-logichop-ga-el+9 more
JS Globals
gtagdataLayer
FAQ

Frequently Asked Questions about Logic Hop Google Analytics Add-on