
WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics Security & Risk Analysis
wordpress.org/plugins/wp-google-analytics-eventsTrack Google Analytics Events on your website - Enables you to send an event when a user Scrolls or Click an element on your website.
Is WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics Safe to Use in 2026?
Use With Caution
Score 61/100WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "wp-google-analytics-events" plugin v2.8.2 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and performing nonce checks on a reasonable number of entry points. However, a significant concern arises from the presence of one AJAX handler lacking authentication checks, creating a potential avenue for unauthorized actions.
The static analysis also reveals a weakness in output escaping, with only 25% of outputs being properly sanitized. This, combined with two flows with unsanitized paths identified during taint analysis, suggests a moderate risk of Cross-Site Scripting (XSS) vulnerabilities, particularly as Cross-Site Scripting is listed as a common vulnerability type in its history.
The plugin's vulnerability history is a major red flag. With two known CVEs, one of which is currently unpatched, and both being medium severity, it indicates a pattern of past security flaws. The common vulnerability types of Exposure of Sensitive Information and XSS further reinforce the concerns about input sanitization and output escaping. The fact that the last vulnerability was in late 2025 is also concerning, as it implies a lack of recent security attention or that the found vulnerabilities are future-dated. Overall, while the plugin has some good security implementations, the unpatched vulnerability, the unprotected AJAX endpoint, and the historically recurring XSS risk necessitate careful consideration and prompt patching.
Key Concerns
- Unpatched CVE found
- AJAX handler without auth check
- Low percentage of properly escaped output
- Flows with unsanitized paths found
- Two medium severity CVEs in history
WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Google Analytics Events <= 2.8.2 - Unauthenticated Information Exposure
WP Google Analytics Events <= 2.8.0 - Reflected Cross-Site Scripting
WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics Code Analysis
Output Escaping
Data Flow Analysis
WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics Attack Surface
AJAX Handlers 10
Shortcodes 2
WordPress Hooks 20
Maintenance & Trust
WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics Maintenance & Trust
Maintenance Signals
Community Trust
WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics Alternatives
Analytics Cat – Google Analytics Made Easy
analytics-cat
Analytics Cat - Google Analytics Lets You Add Your Google Analytics / Universal Analytics Tracking Code To Your Site With Ease.
HT Easy GA4 – Google Analytics WordPress Plugin
ht-easy-google-analytics
HT Easy GA4 - Google Analytics WordPress Plugin enables tracking user behavior and viewing Google Analytics dashboard reports from your website.
Simple Universal Google Analytics
simple-universal-google-analytics
Enable Universal Google Analytics tracking option on your WordPress site. Add tracking code to every page with WordPress Google Analytics plugin.
Analytics Tracker
analytics-tracker
Analytics Tracker makes it super easy to add Google Analytics tracking code on your site
Integrate GA4 Google Analytics
integrate-ga4-google-analytics
A simple, lightweight plugin to easily integrate Google Analytics GA4 tracking into your WordPress site.
WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics Developer Profile
3 plugins · 8K total installs
How We Detect WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-google-analytics-events/assets/js/admin-scripts.js/wp-content/plugins/wp-google-analytics-events/assets/css/admin-styles.css/wp-content/plugins/wp-google-analytics-events/assets/js/frontend-scripts.jswp-content/plugins/wp-google-analytics-events/assets/js/admin-scripts.jswp-content/plugins/wp-google-analytics-events/assets/js/frontend-scripts.jswp-google-analytics-events/assets/css/admin-styles.css?ver=wp-google-analytics-events/assets/js/admin-scripts.js?ver=wp-google-analytics-events/assets/js/frontend-scripts.js?ver=HTML / DOM Fingerprints
wpgae_event_typewpgae_event_selectorwpflow_save_viewga_events_optionswpgae_typeactionwpgae_event_selectorwpgae_event_typeevent_idviewId+2 morewpflow_add_eventwpflow_edit_eventwpflow_delete_eventwpflow_save_viewwpflow_ga_disconnectwpflow_get_event_json+4 more