Really Simple Google Tag Manager (GTM) Security & Risk Analysis

wordpress.org/plugins/really-simple-google-tag-manager

Easily Enables Google Tag Manager on all pages of any Website.

4K active installs v1.1.0 PHP + WP 5.0+ Updated Feb 26, 2026
googlegoogle-tag-managergoogletagreally-simple-google-tag-managertagmanager
100
A · Safe
CVEs total1
Unpatched0
Last CVEMar 31, 2023
Download
Safety Verdict

Is Really Simple Google Tag Manager (GTM) Safe to Use in 2026?

Generally Safe

Score 100/100

Really Simple Google Tag Manager (GTM) has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 31, 2023Updated 1mo ago
Risk Assessment

The "really-simple-google-tag-manager" plugin v1.1.0 presents a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and generally performing adequate output escaping (69% properly escaped), there are significant concerns regarding its attack surface and the absence of critical security checks. The presence of one AJAX handler without authentication is a major red flag, as it represents a direct, unprotected entry point into the plugin's functionality. This can be exploited by unauthenticated users to trigger actions or access data that should be protected. The plugin's vulnerability history shows one known medium-severity CVE, which was last recorded in March 2023 and is marked as currently patched. While this is positive, the existence of a past vulnerability, even if medium, suggests that the plugin has had exploitable flaws. The overall lack of critical findings in taint analysis is encouraging, but the unprotected AJAX handler is a significant weakness that outweighs the positive code signals.

Key Concerns

  • Unprotected AJAX handler
  • Moderate output escaping (69% proper)
  • 1 known medium CVE (historical)
Vulnerabilities
1

Really Simple Google Tag Manager (GTM) Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-23801medium · 4.3Cross-Site Request Forgery (CSRF)

Really Simple Google Tag Manager <= 1.0.6 - Cross-Site Request Forgery via plugin_activation

Mar 31, 2023 Patched in 1.0.7 (298d)
Code Analysis
Analyzed Mar 16, 2026

Really Simple Google Tag Manager (GTM) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
52 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

69% escaped75 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
process_data (admin\class-diagnostic-data.php:166)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Really Simple Google Tag Manager (GTM) Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_simple_googletag_diagnostic_dataadmin\class-diagnostic-data.php:101
WordPress Hooks 10
actionadmin_menuadmin\admin-init.php:12
actionadmin_initadmin\admin-init.php:13
actioninitadmin\admin-init.php:14
actionadmin_noticesadmin\class-diagnostic-data.php:97
actionadmin_menuadmin\Recommended_Plugins.php:78
actionadmin_enqueue_scriptsadmin\Recommended_Plugins.php:79
actioninitincludes\class.simple-googletag.php:29
actionplugins_loadedincludes\class.simple-googletag.php:30
actionwp_headincludes\class.simple-googletag.php:45
actionwp_body_openincludes\class.simple-googletag.php:46
Maintenance & Trust

Really Simple Google Tag Manager (GTM) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version
Downloads27K

Community Trust

Rating0/100
Number of ratings0
Active installs4K
Developer Profile

Really Simple Google Tag Manager (GTM) Developer Profile

HT Plugins

23 plugins · 64K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
124 days
View full developer profile
Detection Fingerprints

How We Detect Really Simple Google Tag Manager (GTM)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/really-simple-google-tag-manager/assets/css/backend.css/wp-content/plugins/really-simple-google-tag-manager/assets/css/frontend.css/wp-content/plugins/really-simple-google-tag-manager/assets/js/backend.js/wp-content/plugins/really-simple-google-tag-manager/assets/js/frontend.js
Script Paths
/wp-content/plugins/really-simple-google-tag-manager/assets/js/backend.js/wp-content/plugins/really-simple-google-tag-manager/assets/js/frontend.js
Version Parameters
really-simple-google-tag-manager/assets/css/backend.css?ver=really-simple-google-tag-manager/assets/css/frontend.css?ver=really-simple-google-tag-manager/assets/js/backend.js?ver=really-simple-google-tag-manager/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
htrp-admin-tab-panehtrp-activehtrp-extension-admin-tab-areahtrp-admin-tabsfilter-links
JS Globals
htrp_params
FAQ

Frequently Asked Questions about Really Simple Google Tag Manager (GTM)