PLUGIN SECURITY

Is Google Analytics For Wordpress safe?

The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.

What this plugin does

  • Slug: google-analytics-for-wordpress
  • Author: chriscct7
  • 2000000+ active installs
  • 90/100 rating (3148 reviews on wordpress.org)
  • 276805029 all-time downloads
  • On WordPress.org since 2007-09-14

analyticsgoogle analyticsgoogle analytics dashboardwebsite analyticsWordPress analytics

Maintenance status

  • Latest known version: 11.1.2
  • Last updated: 2026-08-19 6:50pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.2+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

7 known CVEs on file for Google Analytics For Wordpress. Reported between 2014 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-11366 MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 11.1.0 Improper Authentication Unknown < 11.1.0 11.1.0 2026-08-04 ✓ fixed in latest
CVE-2026-5371 MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 10.1.3 Missing Authorization High 7.1 < 10.1.3 10.1.3 2026-05-12 ✓ fixed in latest
CVE-2023-52220 MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 8.22.0 Missing Authorization Medium 4.3 < 8.22.0 8.22.0 2024-01-05 ✓ fixed in latest
CVE-2023-23999 MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 8.14.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 8.14.1 8.14.1 2023-05-10 ✓ fixed in latest
CVE-2023-0081 MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 8.12.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 8.12.1 8.12.1 2023-01-13 ✓ fixed in latest
CVE-2022-3904 MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 8.9.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 8.9.1 8.9.1 2022-12-23 ✓ fixed in latest
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 7.2.0 Unknown < 7.2.0 7.2.0 2018-12-07 ✓ fixed in latest
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 7.2.0 Unknown < 7.2.0 7.2.0 2018-09-18 ✓ fixed in latest
+ 15 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.4.5 Unknown < 5.4.5 5.4.5 2015-08-10 ✓ fixed in latest
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.4 Unknown < 5.4 5.4 2015-04-20 ✓ fixed in latest
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.3.3 Unknown < 5.3.3 5.3.3 2015-03-19 ✓ fixed in latest
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.3.3 Unknown < 5.3.3 5.3.3 2015-03-06 ✓ fixed in latest
CVE-2014-9174 MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.1.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 5.1.3 5.1.3 2014-11-26 ✓ fixed in latest
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 7.2.0 Unknown < 7.2.0 7.2.0 ✓ fixed in latest
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.4.5 Unknown < 5.4.5 5.4.5 ✓ fixed in latest
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.4 Unknown < 5.4 5.4 ✓ fixed in latest
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.3.3 Unknown < 5.3.3 5.3.3 ✓ fixed in latest
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.3.3 Unknown < 5.3.3 5.3.3 ✓ fixed in latest
Google Analytics by Yoast <= 5.3.2 - Cross-Site Scripting (XSS) Unknown < 5.3.3 5.3.3 ✓ fixed in latest
Google Analytics by Yoast <= 5.3.2 - Stored Cross-Site Scripting (XSS) Unknown < 5.3.3 5.3.3 ✓ fixed in latest
Google Analytics by Yoast < 5.4 - Unauthenticated Cross-Site Scripting (XSS) Unknown < 5.4 5.4 ✓ fixed in latest
Google Analytics by Yoast <= 5.4.4 - Authenticated Stored Cross-Site Scripting (XSS) Unknown < 5.4.5 5.4.5 ✓ fixed in latest
Google Analytics by Monster Insights < 7.2.0 - Authenticated Stored Cross-Site Scripting (XSS) Unknown < 7.2.0 7.2.0 ✓ fixed in latest

How to fix it

Keep Google Analytics For Wordpress updated — 11.1.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.