
WP Tag Manager Event Security & Risk Analysis
wordpress.org/plugins/wp-tag-manager-eventAn easy way to create and manage your Google Analytics events
Is WP Tag Manager Event Safe to Use in 2026?
Generally Safe
Score 85/100WP Tag Manager Event has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-tag-manager-event" v1.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) suggests a limited interaction with user-provided input, which is a significant security benefit. Furthermore, the code analysis revealed no dangerous functions, file operations, or external HTTP requests, all of which are positive indicators. The presence of nonce and capability checks, while limited in number, indicates an awareness of security best practices for the code that does exist. The lack of any recorded vulnerabilities or CVEs in its history further supports a notion of a well-developed and secure plugin.
However, a notable concern arises from the handling of SQL queries. All six identified SQL queries are executed without the use of prepared statements. This practice significantly increases the risk of SQL injection vulnerabilities, especially if any of the data used in these queries originates from user input, even if that input is not directly exposed through the analyzed entry points. While the taint analysis did not reveal any unsanitized flows, this could be due to the limited entry points or the nature of the data processed by the plugin, and does not negate the risk posed by raw SQL queries. The moderate percentage of properly escaped output also warrants attention, as unescaped output can lead to cross-site scripting (XSS) vulnerabilities.
In conclusion, the "wp-tag-manager-event" plugin has a generally good security foundation due to its minimal attack surface and lack of historical vulnerabilities. The strengths lie in its contained code and responsible management of external interactions. The primary weakness is the prevalent use of raw SQL queries, which presents a significant, albeit currently theoretical, risk of SQL injection. Addressing this would be a crucial step in solidifying its security.
Key Concerns
- SQL queries not using prepared statements
- Output escaping not consistently applied
WP Tag Manager Event Security Vulnerabilities
WP Tag Manager Event Code Analysis
SQL Query Safety
Output Escaping
WP Tag Manager Event Attack Surface
WordPress Hooks 5
Maintenance & Trust
WP Tag Manager Event Maintenance & Trust
Maintenance Signals
Community Trust
WP Tag Manager Event Alternatives
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
PixelYourSite – Your smart PIXEL (TAG) & API Manager
pixelyoursite
Add Meta Pixel with Conversion API, Google Analytics (GA4) + Consent Mode, Google Tag Manager, and Head & Footer scripts.
Beehive Analytics – Google Analytics Dashboard
beehive-analytics
View visitor stats and track user behavior from within WordPress. A Google Analytics plugin with dashboard reports and Google Tag Manager support.
Event Tracking for Gravity Forms
gravity-forms-google-analytics-event-tracking
Easily add event tracking using Gravity Forms and your Google Analytics or Google Tag Manager account. Supports Google Analytics v3 and Gravity Forms …
Google Analytics and Google Tag Manager
wk-google-analytics
Google Analytics or Google Tag Manager for WordPress without tracking your own visits.
WP Tag Manager Event Developer Profile
3 plugins · 1K total installs
How We Detect WP Tag Manager Event
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-tag-manager-event/js/wp-tag-manager-event.js/wp-content/plugins/wp-tag-manager-event/js/wp-tag-manager-backend.js/wp-content/plugins/wp-tag-manager-event/js/wp-tag-manager-event.js/wp-content/plugins/wp-tag-manager-event/js/wp-tag-manager-backend.jswp-tag-manager-event/js/wp-tag-manager-event.js?ver=wp-tag-manager-event/js/wp-tag-manager-backend.js?ver=HTML / DOM Fingerprints
data-iddata-eventcategorydata-eventactiondata-eventlabeldata-selectordata-element+1 more