
Easy Google Analytics Toolkit Security & Risk Analysis
wordpress.org/plugins/scand-easy-ga-toolkitEasy Google Analytics Toolkit: analytics code integration on the WordPress website with setting up custom selectors to be checked
Is Easy Google Analytics Toolkit Safe to Use in 2026?
Generally Safe
Score 92/100Easy Google Analytics Toolkit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "scand-easy-ga-toolkit" v1.0.6 plugin exhibits a generally positive security posture, with no known past vulnerabilities or critical issues identified in the static analysis. The absence of raw SQL queries and external HTTP requests are strong indicators of good development practices. The plugin also demonstrates a commitment to security by including nonce checks, which are crucial for preventing cross-site request forgery attacks, especially for its single AJAX handler.
However, there are some areas for improvement. The most significant concern is the low percentage of properly escaped output. With 42 total outputs and only 14% properly escaped, there is a high risk of cross-site scripting (XSS) vulnerabilities. The taint analysis, while not flagging critical or high severity issues, did reveal three flows with unsanitized paths, which could potentially be exploited if combined with other weaknesses. Furthermore, the plugin lacks capability checks on its entry points, meaning that users with lower privileges might be able to trigger certain functionalities, which could be problematic depending on what the AJAX handler performs.
In conclusion, while the plugin avoids many common pitfalls like unpatched CVEs and raw SQL, the significant lack of output escaping presents a substantial risk. The absence of capability checks on the AJAX handler is another area of concern. Addressing the output escaping issues and implementing capability checks would significantly enhance the plugin's security.
Key Concerns
- Low percentage of properly escaped output
- Unsanitized paths in taint flows
- Missing capability checks on entry points
Easy Google Analytics Toolkit Security Vulnerabilities
Easy Google Analytics Toolkit Code Analysis
Output Escaping
Data Flow Analysis
Easy Google Analytics Toolkit Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
Easy Google Analytics Toolkit Maintenance & Trust
Maintenance Signals
Community Trust
Easy Google Analytics Toolkit Alternatives
CAOS | Host Google Analytics Locally
host-analyticsjs-local
The fastest, lightest way to integrate Google Analytics in WordPress.
WP Global Site Tag
wp-global-site-tag
Global Site Tag (gtag.js) is a new Google Analytics replacement – giving you better control while making implementation easier. Using gtag.
Analytics Event Tracking for GTAG
dd-gtag-event-tracking
Adds a button to the WP Editor for easy insertion of links that can be tracked as Events in Google Analytics using the gtag.
Web Vitals
web-vitals
Send Web Vitals to Google Analytics.
ACh Tag Manager
ach-tag-manager
Manage GA4 Measurement ID, Google Tag Manager, and Google Analytics. You can set up Google Analytics 4 property (GA4).
Easy Google Analytics Toolkit Developer Profile
3 plugins · 330 total installs
How We Detect Easy Google Analytics Toolkit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scand-easy-ga-toolkit/includes/css/scand-easy-ga-toolkit-admin.css/wp-content/plugins/scand-easy-ga-toolkit/includes/js/scand-easy-ga-toolkit-admin.jsscand-easy-ga-toolkit/includes/css/scand-easy-ga-toolkit-admin.css?ver=scand-easy-ga-toolkit/includes/js/scand-easy-ga-toolkit-admin.js?ver=HTML / DOM Fingerprints
scand_js_obj