{"id":367249,"date":"2026-09-17T05:24:47","date_gmt":"2026-09-17T05:24:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/goosec\/"},"modified":"2026-09-17T05:24:17","modified_gmt":"2026-09-17T05:24:17","slug":"goosec","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/goosec\/","author":23564064,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.5.5","stable_tag":"1.5.5","tested":"7.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"GOOSEC","header_author":"GIV\u682a\u5f0f\u4f1a\u793e","header_description":"\u30b5\u30a4\u30c8\u306b\u8aad\u307f\u8fbc\u307e\u308c\u3066\u3044\u308b\u5916\u90e8\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u4e00\u89a7\u306b\u3057\u3001\u65b0\u3057\u304f\u5897\u3048\u305f\u901a\u4fe1\u5148\u3092\u304a\u77e5\u3089\u305b\u3057\u307e\u3059\u3002","assets_banners_color":"33383d","last_updated":"2026-09-17 05:24:17","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/www.goosec.site\/","header_author_uri":"https:\/\/www.giv.co.jp\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":23,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.5.5":{"tag":"1.5.5","author":"goosec","date":"2026-09-17 05:24:17","revision":3699581}},"upgrade_notice":{"1.5.0":"<p>The plugin is now named GOOSEC. No action is required.<\/p>","1.4.5":"<p>Hardening changes. If you were scanning an internal address such as 127.0.0.1, that target can no longer be fetched.<\/p>","1.4.4":"<p>Stored credentials are encrypted automatically. SSL verification is enabled when scanning, so check your setup if you scan a site with a self-signed certificate.<\/p>","1.4.3":"<p>The configuration file moves to a new location automatically. No action is required.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3699859,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3699713,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3699713,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.5.5"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3699581,"resolution":"1","location":"assets","locale":"","width":1326,"height":896},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3699581,"resolution":"2","location":"assets","locale":"","width":1511,"height":794},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3699581,"resolution":"3","location":"assets","locale":"","width":1399,"height":868},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3699581,"resolution":"4","location":"assets","locale":"","width":1399,"height":868},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3699581,"resolution":"5","location":"assets","locale":"","width":1567,"height":609}},"screenshots":{"1":"Dashboard \u2014 how many external destinations were found, the risk breakdown, and the state of front page tampering detection","2":"Destination list \u2014 domain, type, risk, the reason for that level, and the URL. Newly appeared destinations are marked NEW","3":"Scan history \u2014 past scans in chronological order","4":"Settings \u2014 pages to scan, HTTP Basic authentication, and front page tampering detection","5":"Trusted domains \u2014 the 73 built-in entries can be reviewed in full on the settings screen"}},"plugin_section":[],"plugin_tags":[282,5603,396,600,281187],"plugin_category":[45,54],"plugin_contributors":[281188],"plugin_business_model":[],"class_list":["post-367249","plugin","type-plugin","status-publish","hentry","plugin_tags-ecommerce","plugin_tags-monitoring","plugin_tags-privacy","plugin_tags-security","plugin_tags-third-party-scripts","plugin_category-ecommerce","plugin_category-security-and-spam-protection","plugin_contributors-goosec","plugin_committers-goosec"],"banners":{"banner":"https:\/\/ps.w.org\/goosec\/assets\/banner-772x250.png?rev=3699713","banner_2x":"https:\/\/ps.w.org\/goosec\/assets\/banner-1544x500.png?rev=3699713","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/goosec\/assets\/icon-128x128.png?rev=3699859","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/goosec\/assets\/screenshot-1.png?rev=3699581","caption":"Dashboard \u2014 how many external destinations were found, the risk breakdown, and the state of front page tampering detection"},{"src":"https:\/\/ps.w.org\/goosec\/assets\/screenshot-2.png?rev=3699581","caption":"Destination list \u2014 domain, type, risk, the reason for that level, and the URL. Newly appeared destinations are marked NEW"},{"src":"https:\/\/ps.w.org\/goosec\/assets\/screenshot-3.png?rev=3699581","caption":"Scan history \u2014 past scans in chronological order"},{"src":"https:\/\/ps.w.org\/goosec\/assets\/screenshot-4.png?rev=3699581","caption":"Settings \u2014 pages to scan, HTTP Basic authentication, and front page tampering detection"},{"src":"https:\/\/ps.w.org\/goosec\/assets\/screenshot-5.png?rev=3699581","caption":"Trusted domains \u2014 the 73 built-in entries can be reviewed in full on the settings screen"}],"raw_content":"<!--section=description-->\n<p><strong>GOOSEC<\/strong> collects the external resources (script, link, iframe, img) that your pages load, and lists them in one place. It tells you when a new destination appears, and when the structure of your front page changes.<\/p>\n\n<p>Tag managers, ads, analytics, payment services \u2014 most sites load scripts that the site owner never explicitly reviewed. Knowing what is actually loaded today is the starting point.<\/p>\n\n<h4>What it does<\/h4>\n\n<ul>\n<li><strong>Lists external destinations<\/strong> \u2014 Extracts <code>script<\/code>, <code>link<\/code>, <code>iframe<\/code> and <code>img<\/code> sources from the HTML of your pages. You can scan several pages, and sites behind HTTP Basic authentication are supported.<\/li>\n<li><strong>Marks what is new<\/strong> \u2014 Compares against the previous scan and flags destinations that appear for the first time.<\/li>\n<li><strong>Shows a three-level risk hint<\/strong> \u2014 Domains in the plugin's built-in trust list (73 entries) or in your own list are shown as low. Direct requests to IP addresses, free top-level domains and URL shorteners are shown as high. Everything else is shown as unverified.<\/li>\n<li><strong>Detects front page tampering<\/strong> \u2014 Compares the tag structure, the resources it loads and the contents of inline scripts against a baseline you approve. Editing article text does not trigger a notification.<\/li>\n<li><strong>Sends email<\/strong> \u2014 Notifies you about new destinations, high-risk destinations and structural changes. The same state is never reported twice.<\/li>\n<li><strong>Runs daily<\/strong> \u2014 One scheduled scan per day, plus a manual scan button.<\/li>\n<li><strong>Keeps history<\/strong> \u2014 Scan history is kept for 365 days; a daily job removes anything older.<\/li>\n<\/ul>\n\n<h4>About the risk levels<\/h4>\n\n<p>High, unverified and low are <strong>a hint about what to look at first, not a verdict about safety<\/strong>. They are decided from the shape of the domain and from whether it appears in a trust list. The plugin does not inspect the content of any request. A destination shown as low is not guaranteed to be safe.<\/p>\n\n<p>The 73 built-in entries can be reviewed in full on the settings screen. You cannot edit that list, but you can add your own domains, and the reason column tells you which list a domain matched.<\/p>\n\n<h4>What it cannot see<\/h4>\n\n<p>The plugin fetches the HTML of your pages from the server and parses it. <strong>Requests that only appear while a visitor's browser is running the page \u2014 for example scripts injected through a tag manager \u2014 are not visible this way.<\/strong> If you need those, see the optional paid service below.<\/p>\n\n<h4>Optional paid service<\/h4>\n\n<p>Everything described above works on its own and contacts no third-party service.<\/p>\n\n<p>If you subscribe to GOOSEC Lite, you can upload the configuration file we issue, and the plugin will show detections made in your visitors' browsers. <strong>This is entirely optional. No request leaves your site until you upload that file.<\/strong> The destinations and the data involved are listed under \"External services\" below.<\/p>\n\n<p>See https:\/\/www.goosec.site\/ for details.<\/p>\n\n<h3>External services<\/h3>\n\n<p><strong>With the free features only, this plugin does not connect to any third-party service.<\/strong> Everything it collects is stored in your own WordPress database. It does fetch your own pages over HTTP in order to scan them.<\/p>\n\n<p>Note for reviewers: <code>includes\/class-risk.php<\/code> contains a static list of domain names (Google, CDNs, payment providers and so on). It is a classification allow-list compared as plain strings against URLs found while scanning the site owner's own pages. The plugin never connects to, enqueues or loads anything from those domains.<\/p>\n\n<p>If you subscribe to GOOSEC Lite and upload <code>goosec_config.js<\/code> from the settings screen, the plugin connects to the following services.<\/p>\n\n<p><strong>1. GOOSEC API (api.goosec.jp) \u2014 retrieving detections<\/strong><\/p>\n\n<ul>\n<li><strong>Sent<\/strong>: the license key, scenario ID and read key issued when you subscribe, plus the date range being requested.<\/li>\n<li><strong>Not sent<\/strong>: your site's content, your posts, or any personal data about your visitors.<\/li>\n<li><strong>When<\/strong>: when an administrator opens the plugin dashboard, and once per day in the background.<\/li>\n<\/ul>\n\n<p><strong>2. GOOSEC detection script (your own subdomain of goosec.jp, and assets.goosec.jp)<\/strong><\/p>\n\n<ul>\n<li>Once enabled, <strong>a script tag is added to every page of your site<\/strong>.<\/li>\n<li><strong>Your visitors' browsers<\/strong> send information about outbound requests occurring on the page (destination URL, page URL, timestamp) to GOOSEC servers.<\/li>\n<li>This is part of the subscribed service and requires a paid plan.<\/li>\n<\/ul>\n\n<p>All of the above services are operated by GIV Inc., the author of this plugin. A paid subscription is required; no data is sent unless you subscribe and upload <code>goosec_config.js<\/code> yourself.<\/p>\n\n<ul>\n<li>Service provider: GIV Inc. (https:\/\/www.giv.co.jp\/)<\/li>\n<li>Service site: https:\/\/www.goosec.site\/<\/li>\n<li>Terms of service: https:\/\/www.goosec.site\/terms<\/li>\n<li>Privacy policy: https:\/\/www.goosec.site\/privacy<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>In your WordPress admin, go to Plugins &gt; Add New and search for GOOSEC.<\/li>\n<li>Click Install Now.<\/li>\n<li>Click Activate.<\/li>\n<li>A GOOSEC entry is added to the admin menu.<\/li>\n<li>Open it and press \"Scan now\" to run the first scan.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20it%20free%3F\"><h3>Is it free?<\/h3><\/dt>\n<dd><p>Yes. Everything listed under \"What it does\" is free, and none of it contacts a third-party service.<\/p><\/dd>\n<dt id=\"how%20is%20this%20different%20from%20a%20waf%20or%20a%20file%20integrity%20monitor%3F\"><h3>How is this different from a WAF or a file integrity monitor?<\/h3><\/dt>\n<dd><p>They protect different layers. A WAF detects and blocks attacks against your server, such as SQL injection or XSS. A file integrity monitor detects changes to files on your server. This plugin lists the external destinations written into your pages and tells you when they change. Use them together.<\/p><\/dd>\n<dt id=\"does%20it%20slow%20down%20my%20site%3F\"><h3>Does it slow down my site?<\/h3><\/dt>\n<dd><p>No. The free scan runs in the background on the server, once a day, and does not affect page rendering for visitors. If you enable the optional paid detection, a script tag is added to every page.<\/p><\/dd>\n<dt id=\"a%20domain%20is%20shown%20as%20high%20risk.%20what%20should%20i%20do%3F\"><h3>A domain is shown as high risk. What should I do?<\/h3><\/dt>\n<dd><p>First check whether it is a service you added yourself. If it is, add it to your trusted list. If you do not recognise it, look into the script that loads it. The level is decided from the shape of the domain alone, so <strong>high does not by itself mean the destination is malicious<\/strong>.<\/p><\/dd>\n<dt id=\"a%20domain%20is%20shown%20as%20low.%20does%20that%20mean%20it%20is%20safe%3F\"><h3>A domain is shown as low. Does that mean it is safe?<\/h3><\/dt>\n<dd><p>No. Low only means the domain is in the built-in trust list or in your own list. The plugin does not inspect what is being sent. Treat the levels as an order in which to look, nothing more.<\/p><\/dd>\n<dt id=\"front%20page%20tampering%20is%20reported%20when%20i%20simply%20update%20my%20site.\"><h3>Front page tampering is reported when I simply update my site.<\/h3><\/dt>\n<dd><p>Structural updates, such as adding a page or changing the design, are reported. Editing article text is not. After an intended change, press \"Set the current state as the new baseline\" on the dashboard. The same state is never reported twice.<\/p><\/dd>\n<dt id=\"can%20it%20detect%20scripts%20that%20are%20loaded%20dynamically%2C%20for%20example%20through%20a%20tag%20manager%3F\"><h3>Can it detect scripts that are loaded dynamically, for example through a tag manager?<\/h3><\/dt>\n<dd><p>Not with the free features. The plugin fetches your page's HTML from the server, and scripts that are added while the page runs in a browser do not appear in that HTML. If you need those, consider the paid plan.<\/p><\/dd>\n<dt id=\"where%20is%20the%20collected%20information%20stored%3F\"><h3>Where is the collected information stored?<\/h3><\/dt>\n<dd><p>Destinations and scan history are stored <strong>only in your own WordPress database<\/strong>. Nothing is sent anywhere else.<\/p>\n\n<p>The HTTP Basic authentication password, and the read key used by the paid plan, are <strong>stored encrypted<\/strong> using a key derived from your wp-config.php salts, and are never printed on screen. Note that anyone who can read wp-config.php can decrypt them; the purpose is to prevent them being read in plain text if the database contents alone are exposed.<\/p><\/dd>\n<dt id=\"if%20i%20delete%20the%20plugin%2C%20is%20the%20data%20removed%3F\"><h3>If I delete the plugin, is the data removed?<\/h3><\/dt>\n<dd><p>Yes. Using Delete in WordPress removes the scan history tables, the settings and the uploaded configuration file. <strong>This cannot be undone.<\/strong> Deactivating does not remove anything, so use Deactivate if you only want to pause.<\/p><\/dd>\n<dt id=\"where%20is%20goosec_config.js%20stored%3F\"><h3>Where is goosec_config.js stored?<\/h3><\/dt>\n<dd><p>In <code>wp-content\/uploads\/goosec\/<\/code>. It does not appear in the Media Library, because that list shows files registered as attachments and this file is not registered as one.<\/p>\n\n<p>Before 1.4.3 the file was stored inside the plugin folder, so updating the plugin could delete it. Updating to 1.4.3 or later moves an existing file to the new location automatically.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.5.5<\/h4>\n\n<ul>\n<li>Rejects configuration files containing a closing script tag, since the configuration is now printed inline.<\/li>\n<li>Skips the one-time migration lookup once it has run, so sites that do not use the paid features no longer check the filesystem on every page load.<\/li>\n<li>No longer writes the uploaded configuration to the uploads directory. The configuration is stored in the database and printed with <code>wp_add_inline_script()<\/code>. Existing installations are migrated automatically and the old file is removed.<\/li>\n<li>Moved the two remaining inline <code>&lt;script&gt;<\/code> blocks in the admin screens to separate files loaded with <code>wp_enqueue_script()<\/code>.<\/li>\n<li>Documented the terms of service alongside the privacy policy in \"External services\".<\/li>\n<\/ul>\n\n<h4>1.5.3<\/h4>\n\n<ul>\n<li>Set distinct Plugin URI and Author URI in the plugin header<\/li>\n<\/ul>\n\n<h4>1.5.2<\/h4>\n\n<ul>\n<li>Escaped the table names passed to direct database queries<\/li>\n<\/ul>\n\n<h4>1.5.1<\/h4>\n\n<ul>\n<li>Rewrote the readme in English<\/li>\n<li>Replaced forbidden and discouraged file functions with the WordPress filesystem API<\/li>\n<li>Escaped badge output through wp_kses_post()<\/li>\n<li>Documented the direct queries against the plugin's own tables<\/li>\n<li>Prefixed the variables used in uninstall.php<\/li>\n<\/ul>\n\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>Renamed the plugin to GOOSEC<\/li>\n<li>Reworded on-screen and email text to match what the plugin actually does<\/li>\n<li>Replaced forbidden and discouraged file functions with the WordPress filesystem API<\/li>\n<li>Escaped badge output, and documented the direct database queries against the plugin's own tables<\/li>\n<\/ul>\n\n<h4>1.4.9<\/h4>\n\n<ul>\n<li>Removed icons that were still present in email headings<\/li>\n<\/ul>\n\n<h4>1.4.8<\/h4>\n\n<ul>\n<li>Reworded the dashboard subtitle to match what the plugin actually does<\/li>\n<li>Fixed the action column in the destination list wrapping and breaking row heights<\/li>\n<\/ul>\n\n<h4>1.4.7<\/h4>\n\n<ul>\n<li>Confirmed compatibility with WordPress 7.1<\/li>\n<\/ul>\n\n<h4>1.4.6<\/h4>\n\n<ul>\n<li>Included the full GPLv2 licence text<\/li>\n<li>Removed an unused Domain Path declaration<\/li>\n<li>Corrected the readme tags (the plugin does not perform malware detection)<\/li>\n<\/ul>\n\n<h4>1.4.5<\/h4>\n\n<ul>\n<li>Validated the format of the detection token and hardened its escaping when written to a page<\/li>\n<li>HTTP Basic credentials are now sent only when the scan target is your own site\n(use the <code>goosec_basic_auth_hosts<\/code> filter if another host is required)<\/li>\n<li>Scans now use <code>wp_safe_remote_get()<\/code>, so loopback and internal addresses cannot be targeted<\/li>\n<li>Uploaded files are checked to confirm they are a GOOSEC configuration file<\/li>\n<\/ul>\n\n<h4>1.4.4<\/h4>\n\n<ul>\n<li>The HTTP Basic password and the read key are now stored encrypted\n(existing values are encrypted automatically on update)<\/li>\n<li>The HTTP Basic password is no longer printed into the settings screen<\/li>\n<li>Fixed passwords containing quotes or backslashes being stored incorrectly<\/li>\n<li>SSL certificates are now verified when scanning\n(use the <code>goosec_scan_sslverify<\/code> filter if you must disable this, for example for self-signed certificates)<\/li>\n<\/ul>\n\n<h4>1.4.3<\/h4>\n\n<ul>\n<li>Moved <code>goosec_config.js<\/code> to <code>wp-content\/uploads\/goosec\/<\/code>\n(it was stored inside the plugin folder, so updating the plugin could delete it.\nAn existing file is moved automatically on update)<\/li>\n<li>The admin screen now tells you when the configuration file is missing<\/li>\n<li>Scan history is now pruned by a daily job\n(previously it only happened when the history screen was opened)<\/li>\n<li>Deleting the plugin now removes its tables, settings and uploaded file<\/li>\n<\/ul>\n\n<h4>1.4.2<\/h4>\n\n<ul>\n<li>Removed icons from screen titles and email headings<\/li>\n<li>Fixed the notification email referring to a button name that no longer existed on screen<\/li>\n<\/ul>\n\n<h4>1.4.1<\/h4>\n\n<ul>\n<li>Fixed column widths in the destination list<\/li>\n<li>Fixed long URLs not using the available width, and the three-line clamp not applying<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>Fixed front page tampering being reported every day for the same unchanged state<\/li>\n<li>Front page tampering is no longer reported for article text edits\n(the plugin now compares tag structure, loaded resources and inline script contents, including the head)<\/li>\n<li>The dashboard and the email now say what the baseline is and which button resets it<\/li>\n<li>The reason column now says whether a domain is trusted by the built-in list or by your own list<\/li>\n<li>The built-in trust list can be reviewed in full on the settings screen<\/li>\n<li>With the paid plan enabled, the plugin no longer shows its own risk levels\n(detection results come from GOOSEC, so two different verdicts are never shown for one destination)<\/li>\n<li>With the paid plan enabled, a link to the GOOSEC console is shown<\/li>\n<\/ul>\n\n<h4>1.3.1<\/h4>\n\n<ul>\n<li>Fixed the detection type column wrapping mid-word<\/li>\n<li>Fixed row heights breaking when a URL was long<\/li>\n<li>The summary now says which numbers it is counting<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Detection names and priorities now follow the GOOSEC service<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Added front page tampering detection<\/li>\n<li>Added email notifications<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added scan history<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First release<\/li>\n<\/ul>","raw_excerpt":"Lists the external scripts loaded by your pages and tells you when a new destination appears.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/367249","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=367249"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/goosec"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=367249"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=367249"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=367249"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=367249"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=367249"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=367249"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}