Simple Analytics – Tag Manager Security & Risk Analysis

wordpress.org/plugins/simple-analitycs-tag-manager

It allows you to very simply configure your code: Google Analytics and Google Tag Manager.

1K active installs v1.0 PHP 5.2+ WP 5.2+ Updated Sep 1, 2020
googlegoogle-analyticsgoogle-tag-managersimple-google-analyticssimple-google-tag-manager
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Simple Analytics – Tag Manager Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Analytics – Tag Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "simple-analitycs-tag-manager" plugin version 1.0 exhibits a generally good security posture from a static analysis perspective, with no observed dangerous functions, no raw SQL queries, and no file operations or external HTTP requests. The absence of any recorded CVEs and a clean vulnerability history further suggest a lack of previously discovered exploitable flaws.

However, a significant concern arises from the complete lack of output escaping. This means that any data processed by the plugin and then displayed to users could potentially be manipulated to inject malicious code, such as cross-site scripting (XSS) attacks. While the attack surface appears minimal and there are no identified taint flows or critical vulnerabilities in the current analysis, the unescaped output represents a notable weakness that could be exploited if dynamic data is not handled securely.

In conclusion, while the plugin demonstrates strengths in avoiding common pitfalls like unauthenticated entry points and raw SQL, the critical omission of output escaping is a serious security gap. Until this is addressed, the plugin remains vulnerable to client-side attacks. The clean vulnerability history is positive, but it doesn't mitigate the immediate risk posed by the identified code signal deficiency.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

Simple Analytics – Tag Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Analytics – Tag Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Attack Surface

Simple Analytics – Tag Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menusimple-analitycs-tag-manager.php:17
actionadmin_initsimple-analitycs-tag-manager.php:18
actionwp_headsimple-analitycs-tag-manager.php:127
actionwp_body_opensimple-analitycs-tag-manager.php:128
actioninitsimple-analitycs-tag-manager.php:131
Maintenance & Trust

Simple Analytics – Tag Manager Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedSep 1, 2020
PHP min version5.2
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

Simple Analytics – Tag Manager Developer Profile

Miguel Fuentes

5 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Analytics – Tag Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://www.googletagmanager.com/gtag/js?id=https://www.googletagmanager.com/gtm.js?id=

HTML / DOM Fingerprints

HTML Comments
<!-- Global site tag (gtag.js) - Google Analytics --><!-- Google Tag Manager --><!-- End Google Tag Manager --><!-- Google Tag Manager (noscript) -->+1 more
Data Attributes
name='kwp_simple_ga_gtm_settings[kwp_simple_text_field_ga]'name='kwp_simple_ga_gtm_settings[kwp_simple_text_field_gtm]'
JS Globals
dataLayergtagwindow.dataLayer
FAQ

Frequently Asked Questions about Simple Analytics – Tag Manager