Sig GA4 Widget Security & Risk Analysis

wordpress.org/plugins/sig-ga4-widget

Show your google analytics 4 visit data on your template widget.

60 active installs v1.1.1 PHP + WP 5.9+ Updated Jul 29, 2025
analyticsga4googlepixnettracking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sig GA4 Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Sig GA4 Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The 'sig-ga4-widget' plugin v1.1.1 demonstrates a generally good security posture, particularly in its handling of database interactions and protection against direct cross-site scripting (XSS) via AJAX. The absence of known CVEs, direct SQL injections, and critical taint analysis flows is highly positive. The plugin utilizes prepared statements for all SQL queries, which is a fundamental security best practice. Nonce checks are implemented on its AJAX handlers, and there are no identified shortcodes, cron events, or REST API routes that could serve as attack vectors without proper authorization checks.

Key Concerns

  • Output escaping is only 62% properly escaped
  • No capability checks on AJAX handlers
  • Bundled Guzzle library may be outdated
Vulnerabilities
None known

Sig GA4 Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sig GA4 Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
33
53 escaped
Nonce Checks
2
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

62% escaped86 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
add_wpajax_widget_data (sig-ga4-widget.php:252)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sig GA4 Widget Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_siga4w-widgetsig-ga4-widget.php:52
noprivwp_ajax_siga4w-widgetsig-ga4-widget.php:53
authwp_ajax_siga4w-deletesig-ga4-widget.php:54
WordPress Hooks 8
actionwidgets_initclasses\widget.php:356
actionwp_enqueue_scriptssig-ga4-widget.php:42
actionadmin_menusig-ga4-widget.php:44
actionadmin_enqueue_scriptssig-ga4-widget.php:46
actionadmin_initsig-ga4-widget.php:48
filterthe_contentsig-ga4-widget.php:50
filterupload_mimessig-ga4-widget.php:187
actionplugins_loadedsig-ga4-widget.php:392
Maintenance & Trust

Sig GA4 Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 29, 2025
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

Sig GA4 Widget Developer Profile

Simon

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sig GA4 Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sig-ga4-widget/assets/css/bootstrap-grid.min.css/wp-content/plugins/sig-ga4-widget/assets/js/morris.css/wp-content/plugins/sig-ga4-widget/assets/js/raphael-min.js/wp-content/plugins/sig-ga4-widget/assets/js/morris.min.js

HTML / DOM Fingerprints

CSS Classes
siga4w-container
Data Attributes
data-siga4w-widget-id
JS Globals
SIGA4W_AJAX_URLSIGA4W_SETTINGS
Shortcode Output
[siga4w_widget]
FAQ

Frequently Asked Questions about Sig GA4 Widget