Simple Analytics Tag Security & Risk Analysis

wordpress.org/plugins/simple-analytics-tag-beta

Placing Google Analytics and Google Tagmanager tags on your website made easy.

50 active installs v1.4.1 PHP + WP 5.2+ Updated Oct 6, 2020
google-analyticsgoogle-idgoogle-tagmanagergtmua
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Analytics Tag Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Analytics Tag has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "simple-analytics-tag-beta" v1.4.1 demonstrates a strong security posture based on the provided static analysis. The absence of any identified vulnerabilities in its history and the lack of critical or high-severity findings in the taint analysis are positive indicators. The code also shows good practices in terms of SQL queries being prepared and a high percentage of output being properly escaped, minimizing common injection and XSS risks. The plugin's attack surface is negligible, with no AJAX handlers, REST API routes, shortcodes, or cron events, further reducing potential entry points for attackers. The presence of only two external HTTP requests, without information on their security, is a minor point of attention but not a definitive risk based on the data. The plugin's security appears robust due to the absence of known vulnerabilities and a generally clean code analysis. However, the complete lack of nonce and capability checks across all entry points, combined with the absence of taint flow analysis, presents an unknown risk. While the current code might be inherently safe, this lack of explicit security mechanisms means that future modifications or unforeseen interactions could introduce vulnerabilities without being immediately apparent. The plugin has a perfect vulnerability history, which is excellent, but it also means there's no established pattern of security fixes to analyze. Overall, the plugin is currently in a very good security state, but the lack of explicit authorization checks for potential future entry points is a potential area for concern.

Key Concerns

  • No nonce checks on any entry points
  • No capability checks on any entry points
  • Taint analysis could not be performed
  • External HTTP requests without security details
Vulnerabilities
None known

Simple Analytics Tag Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Simple Analytics Tag Release Timeline

v1.4.1Current
v1.3.2
v1.3.1
v1.3
v1.2
v1.1
v1.0
v0.5
Code Analysis
Analyzed Mar 16, 2026

Simple Analytics Tag Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
36 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

90% escaped40 total outputs
Attack Surface

Simple Analytics Tag Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwp_headincludes\analytics.function.php:36
actionwp_body_openincludes\analytics.function.php:59
actionwp_footerincludes\analytics.function.php:82
actionadmin_menuincludes\nav.function.php:19
actionadmin_initincludes\wpadmin.function.php:54
actionadmin_initload.php:12
Maintenance & Trust

Simple Analytics Tag Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 6, 2020
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Simple Analytics Tag Developer Profile

Rik

5 plugins · 6K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Analytics Tag

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- Global site tag (gtag.js) - Google Analytics --><!-- End Google Tag Manager --><!-- Google Tag Manager (noscript) --><!-- End Google Tag Manager (noscript) -->
JS Globals
window.dataLayerfunction gtag(){dataLayer.push(arguments);}
FAQ

Frequently Asked Questions about Simple Analytics Tag