
Local Google Analytics for WordPress – caches external requests Security & Risk Analysis
wordpress.org/plugins/simple-google-analyticsPlugs in Google Analytics code to your website pages and caches it, so the website loads faster.
Is Local Google Analytics for WordPress – caches external requests Safe to Use in 2026?
Generally Safe
Score 100/100Local Google Analytics for WordPress – caches external requests has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simple-google-analytics" v3.2.9 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of known vulnerabilities in its history is a significant strength, suggesting a history of responsible development and patching. Furthermore, the static analysis reveals a remarkably small attack surface, with no AJAX handlers, REST API routes, or shortcodes exposed without authentication. This is a strong indicator of good security practices in terms of limiting potential entry points for attackers.
However, there are areas of concern that warrant attention. The most significant is the handling of SQL queries, with 100% of the identified queries not using prepared statements. This practice, coupled with file operations and external HTTP requests, could introduce risks if user-supplied data is not meticulously sanitized before being used in these contexts. The low percentage of properly escaped output also raises flags, as it increases the potential for cross-site scripting (XSS) vulnerabilities if user-generated content is not handled securely. The absence of nonce checks and the limited capability checks suggest that some actions within the plugin might not be adequately protected against CSRF attacks or unauthorized access.
In conclusion, while the plugin benefits from a clean vulnerability history and a small attack surface, the lack of prepared statements for SQL queries, insufficient output escaping, and minimal nonce/capability checks represent potential weaknesses. Developers should prioritize addressing these code-level concerns to further harden the plugin's security and mitigate potential risks.
Key Concerns
- SQL queries without prepared statements
- Low percentage of properly escaped output
- No nonce checks
- Limited capability checks
Local Google Analytics for WordPress – caches external requests Security Vulnerabilities
Local Google Analytics for WordPress – caches external requests Code Analysis
SQL Query Safety
Output Escaping
Local Google Analytics for WordPress – caches external requests Attack Surface
WordPress Hooks 25
Scheduled Events 4
Maintenance & Trust
Local Google Analytics for WordPress – caches external requests Maintenance & Trust
Maintenance Signals
Community Trust
Local Google Analytics for WordPress – caches external requests Alternatives
Lara's Google Analytics (GA4)
lara-google-analytics
Full width Google Analytics dashboard widget for Wordpress admin interface, which also inserts latest Google Analytics (GA4) tracking code to your pag …
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
google-analytics-dashboard-for-wp
Connects Google Analytics with your WordPress site. Displays stats to help you understand your users and site content on a whole new level!
Analytics Insights – Google Analytics Dashboard for WordPress
analytics-insights
A full-featured and entirely free Google Analytics Dashboard plugin for WordPress. Displays stats to help you to better understand your site content.
GAinWP Google Analytics Integration for WordPress
ga-in
Enable Google Analytics tracking and reporting dashboards in your WordPress site in just seconds.
Metrics Query
metrics-query
Connects Google Analytics with your WordPress site. Displays stats to help you understand your users and site content on a whole new level!
Local Google Analytics for WordPress – caches external requests Developer Profile
2 plugins · 6K total installs
How We Detect Local Google Analytics for WordPress – caches external requests
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-google-analytics/includes/js/admin-scripts.min.js/wp-content/plugins/simple-google-analytics/assets/css/bootstrap-grid.min.css/wp-content/plugins/simple-google-analytics/assets/css/factory-forms.min.css/wp-content/plugins/simple-google-analytics/assets/css/factory-pages.min.css/wp-content/plugins/simple-google-analytics/assets/css/factory-templates.min.css/wp-content/plugins/simple-google-analytics/assets/css/style.css/wp-content/plugins/simple-google-analytics/assets/js/bootstrap.bundle.min.js/wp-content/plugins/simple-google-analytics/assets/js/vue.min.js/wp-content/plugins/simple-google-analytics/assets/js/vue-multiselect.min.js/wp-content/plugins/simple-google-analytics/assets/js/admin-scripts.min.jssimple-google-analytics/includes/js/admin-scripts.min.js?ver=simple-google-analytics/assets/css/bootstrap-grid.min.css?ver=simple-google-analytics/assets/css/factory-forms.min.css?ver=simple-google-analytics/assets/css/factory-pages.min.css?ver=simple-google-analytics/assets/css/factory-templates.min.css?ver=simple-google-analytics/assets/css/style.css?ver=simple-google-analytics/assets/js/bootstrap.bundle.min.js?ver=simple-google-analytics/assets/js/vue.min.js?ver=simple-google-analytics/assets/js/vue-multiselect.min.js?ver=simple-google-analytics/assets/js/admin-scripts.min.js?ver=HTML / DOM Fingerprints
wbcr-gac-tracking-code<!-- Google Analytics Local by Webcraftic Local Google Analytics --><!-- @formatter:off --><!-- @formatter:on --><!-- Builded by Webcraftic Factory -->data-ga-tracking-codedata-ga-adjusted-bounce-ratedata-ga-anonymize-ipdata-ga-disable-display-featuresWBCR_AdminPage