Simple Plugin for Google Analytics Security & Risk Analysis

wordpress.org/plugins/overengineer-gasp

An unofficial WordPress plugin for Google Analytics.

30 active installs v1.1.2 PHP 5.6.20+ WP 4.4+ Updated Sep 2, 2019
analyticscookiebotgoogle
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Plugin for Google Analytics Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Plugin for Google Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "overengineer-gasp" v1.1.2 plugin exhibits a generally good security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events, coupled with no external HTTP requests or file operations, significantly limits the plugin's attack surface. Furthermore, the code signals indicate a strong adherence to secure coding practices, with all SQL queries utilizing prepared statements and the presence of capability checks.

However, a notable concern arises from the lack of proper output escaping, with 0% of the 8 identified outputs being escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if the data being output is not already sanitized at its source. The absence of taint analysis results, while indicating no critical or high-severity flows were found, might also suggest an incomplete analysis or a very limited scope of code analyzed. The plugin's vulnerability history is also clear, with no recorded CVEs, suggesting a history of security-conscious development.

In conclusion, while the plugin has a very small attack surface and demonstrates good practices in areas like SQL handling and capability checks, the lack of output escaping is a critical weakness that needs immediate attention. The absence of known vulnerabilities is a positive sign, but it does not negate the risks presented by unescaped output. A more comprehensive taint analysis would further solidify the assessment of its security.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

Simple Plugin for Google Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Simple Plugin for Google Analytics Release Timeline

v1.1.2Current
v1.1.1
v1.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

Simple Plugin for Google Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

Simple Plugin for Google Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuincludes/admin/settings.php:16
actionadmin_initincludes/admin/settings.php:17
actionwp_headincludes/analytics.php:93
actionwp_footerincludes/analytics.php:95
actionplugins_loadedoverengineer-gasp.php:107
Maintenance & Trust

Simple Plugin for Google Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedSep 2, 2019
PHP min version5.6.20
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Simple Plugin for Google Analytics Developer Profile

overengineer

3 plugins · 5K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Plugin for Google Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/overengineer-gasp/assets/js/gasp-backend.js

HTML / DOM Fingerprints

JS Globals
dataLayergtag
FAQ

Frequently Asked Questions about Simple Plugin for Google Analytics