WP Analytics Tag Manager Security & Risk Analysis

wordpress.org/plugins/wp-analytics-tag-manager

WP Analytics Tag Manager is a plug-in that you can easily manage tags embedded Google Analytics, such as Yahoo! analysis.

200 active installs v0.7.0 PHP + WP 3.3+ Updated Mar 2, 2014
analyticsgoogletag-managementtag-manager
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Analytics Tag Manager Safe to Use in 2026?

Generally Safe

Score 85/100

WP Analytics Tag Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'wp-analytics-tag-manager' v0.7.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any discovered AJAX handlers, REST API routes, shortcodes, or cron events with accessible entry points significantly reduces its attack surface. Furthermore, the code signals indicate a positive trend with no dangerous functions, all SQL queries utilizing prepared statements, and a consistent use of nonce and capability checks. The plugin also avoids file operations and external HTTP requests, which are common vectors for security exploits.

However, the analysis does highlight a potential concern regarding output escaping, where only 53% of the 15 identified outputs are properly escaped. This could leave the plugin vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is not correctly sanitized before being displayed. The lack of any recorded historical vulnerabilities, while positive, should be viewed in conjunction with the limited scope of the static analysis, particularly the absence of taint analysis flows. This indicates that while no explicit vulnerabilities are currently known or flagged, a comprehensive security audit should still be considered.

In conclusion, 'wp-analytics-tag-manager' v0.7.0 appears to be developed with security best practices in mind, particularly concerning its limited attack surface and secure database interactions. The primary area for improvement is the consistency of output escaping. The complete absence of historical vulnerabilities is a good sign, but the lack of taint analysis findings suggests that while the surface looks clean, deeper analysis might reveal subtle issues. Overall, the plugin demonstrates a relatively good security profile with a specific area needing attention.

Key Concerns

  • Inconsistent output escaping
Vulnerabilities
None known

WP Analytics Tag Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Analytics Tag Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
8 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

53% escaped15 total outputs
Attack Surface

WP Analytics Tag Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_print_stylessystem\wp_ana_tm_admin_page.php:40
actionadmin_print_scriptssystem\wp_ana_tm_admin_page.php:41
actionadmin_headsystem\wp_ana_tm_admin_page.php:42
actionsave_postsystem\wp_ana_tm_admin_page.php:43
actionplugins_loadedwp-analytics-tag-manager.php:46
actioninitwp-analytics-tag-manager.php:63
actionwp_headwp-analytics-tag-manager.php:70
actionwp_footerwp-analytics-tag-manager.php:71
Maintenance & Trust

WP Analytics Tag Manager Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedMar 2, 2014
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

WP Analytics Tag Manager Developer Profile

niiyz

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Analytics Tag Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-analytics-tag-manager/js/wp_ana_tm.js/wp-content/plugins/wp-analytics-tag-manager/css/wp_ana_tm_admin.css
Script Paths
/wp-content/plugins/wp-analytics-tag-manager/js/wp_ana_tm.js
Version Parameters
wp-analytics-tag-manager/js/wp_ana_tm.js?ver=wp-analytics-tag-manager/css/wp_ana_tm_admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
donation
Data Attributes
name="wp_ana_tag_page_post_id"id="wp_ana_tag_page_post_id"
JS Globals
window.WP_ANA_TAG_Config
FAQ

Frequently Asked Questions about WP Analytics Tag Manager