Simple Universal Google Analytics Security & Risk Analysis

wordpress.org/plugins/simple-universal-google-analytics

Enable Universal Google Analytics tracking option on your WordPress site. Add tracking code to every page with WordPress Google Analytics plugin.

4K active installs v1.0.5 PHP + WP 4.2+ Updated Mar 30, 2023
analyticsgagooglegoogle-analyticstracking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Universal Google Analytics Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Universal Google Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "simple-universal-google-analytics" plugin v1.0.5 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The plugin does not appear to expose any direct attack surface through AJAX, REST API, shortcodes, or cron events without authentication checks. Furthermore, it avoids dangerous functions and file operations, and it has no recorded vulnerabilities or CVEs. This suggests a careful approach to development and a strong track record regarding security.

However, there are areas for improvement. The code signals indicate that only 33% of outputs are properly escaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if the unescaped output contains user-supplied data. While taint analysis found no flows, the limited output escaping warrants attention. The lack of nonce checks on AJAX handlers and the sole capability check, while not flagged as issues in this specific analysis, could be areas to strengthen to further harden the plugin against potential attacks, especially if the plugin were to evolve and introduce new entry points.

In conclusion, the plugin is currently in a good security state with no known critical flaws or historical vulnerabilities. The strengths lie in its minimal attack surface and lack of dangerous code patterns. The primary weakness identified is the insufficient output escaping, which poses a moderate risk. Addressing this would significantly improve the plugin's overall security.

Key Concerns

  • Output escaping only 33% proper
Vulnerabilities
None known

Simple Universal Google Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Universal Google Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped6 total outputs
Attack Surface

Simple Universal Google Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterplugin_action_linksmain.php:29
actionplugins_loadedmain.php:31
actionadmin_initmain.php:32
actionadmin_menumain.php:33
actionwp_headmain.php:34
filteremd_custom_link_attributesmain.php:35
Maintenance & Trust

Simple Universal Google Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMar 30, 2023
PHP min version
Downloads52K

Community Trust

Rating92/100
Number of ratings9
Active installs4K
Developer Profile

Simple Universal Google Analytics Developer Profile

Noor Alam

25 plugins · 157K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
450 days
View full developer profile
Detection Fingerprints

How We Detect Simple Universal Google Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
//www.google-analytics.com/analytics.js

HTML / DOM Fingerprints

HTML Comments
<!-- Tracking code generated with Simple Universal Google Analytics plugin v1.0.5 --><!-- / Simple Universal Google Analytics plugin -->
JS Globals
ga
FAQ

Frequently Asked Questions about Simple Universal Google Analytics