{"id":79023,"date":"2017-12-15T06:06:15","date_gmt":"2017-12-15T06:06:15","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/wp-global-site-tag\/"},"modified":"2026-07-28T02:29:17","modified_gmt":"2026-07-28T02:29:17","slug":"wp-global-site-tag","status":"publish","type":"plugin","link":"https:\/\/szl.wordpress.org\/plugins\/wp-global-site-tag\/","author":15679171,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.0.0","stable_tag":"2.0.0","tested":"7.0.2","requires":"6.3","requires_php":"7.4","requires_plugins":null,"header_name":"WP Global Site Tag","header_author":"Digital Apps","header_description":"This is a short description of what the plugin does. It's displayed in the WordPress admin area.","assets_banners_color":"e2c05b","last_updated":"2026-07-28 02:29:17","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/www.buymeacoffee.com\/wpplugins","header_plugin_uri":"https:\/\/digitalapps.com\/wordpress-plugins\/wp-global-site-tag\/","header_author_uri":"https:\/\/digitalapps.com","rating":5,"author_block_rating":0,"active_installs":7000,"downloads":82152,"num_ratings":3,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.1":{"tag":"1.0.1","author":"digitalapps","date":"2018-03-01 23:10:04"},"1.1.0":{"tag":"1.1.0","author":"digitalapps","date":"2026-07-15 04:10:25"},"1.1.1":{"tag":"1.1.1","author":"digitalapps","date":"2026-07-17 07:19:11"},"2.0.0":{"tag":"2.0.0","author":"digitalapps","date":"2026-07-28 02:29:17"}},"upgrade_notice":{"2.0.0":"<p>Adds the guided read-only GA4 dashboard while preserving existing tracking. Review the Google Cloud setup, installation-mode, privacy, and external-service guidance.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":"3"},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":1804841,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":1804841,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":1804845,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":1804845,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.1","1.1.0","1.1.1","2.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3625295,"resolution":"1","location":"assets","locale":"","width":1265,"height":712},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3625295,"resolution":"2","location":"assets","locale":"","width":1265,"height":712},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3625295,"resolution":"3","location":"assets","locale":"","width":1265,"height":712}},"screenshots":{"1":"The connected Free Analytics dashboard shows key metrics, a seven-day traffic trend, numeric scale, and combined daily values.","2":"Guided read-only Google connection explains data access and managed authorization before the administrator proceeds.","3":"Tracking settings support Google tags, Google Tag Manager containers, additional destinations, Consent Mode v2 defaults, and explicit installation modes."}},"plugin_section":[],"plugin_tags":[223629,193472,1005,233857,23294],"plugin_category":[36],"plugin_contributors":[150144],"plugin_business_model":[],"class_list":["post-79023","plugin","type-plugin","status-publish","hentry","plugin_tags-consent-mode","plugin_tags-ga4","plugin_tags-google-analytics","plugin_tags-google-tag","plugin_tags-google-tag-manager","plugin_category-analytics","plugin_contributors-digitalapps","plugin_committers-digitalapps"],"banners":{"banner":"https:\/\/ps.w.org\/wp-global-site-tag\/assets\/banner-772x250.png?rev=1804845","banner_2x":"https:\/\/ps.w.org\/wp-global-site-tag\/assets\/banner-1544x500.png?rev=1804845","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/wp-global-site-tag\/assets\/icon-128x128.png?rev=1804841","icon_2x":"https:\/\/ps.w.org\/wp-global-site-tag\/assets\/icon-256x256.png?rev=1804841","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/wp-global-site-tag\/assets\/screenshot-1.png?rev=3625295","caption":"The connected Free Analytics dashboard shows key metrics, a seven-day traffic trend, numeric scale, and combined daily values."},{"src":"https:\/\/ps.w.org\/wp-global-site-tag\/assets\/screenshot-2.png?rev=3625295","caption":"Guided read-only Google connection explains data access and managed authorization before the administrator proceeds."},{"src":"https:\/\/ps.w.org\/wp-global-site-tag\/assets\/screenshot-3.png?rev=3625295","caption":"Tracking settings support Google tags, Google Tag Manager containers, additional destinations, Consent Mode v2 defaults, and explicit installation modes."}],"raw_content":"<!--section=description-->\n<p>WP Global Site Tag provides two related tools without mixing their state:<\/p>\n\n<ul>\n<li>Tracking installs a Google tag or Google Tag Manager container on the public site.<\/li>\n<li>Reporting connects an administrator to Google Analytics with read-only access and displays reports inside WordPress.<\/li>\n<\/ul>\n\n<p>You can use either tool independently. Connecting Analytics never enables tracking or silently replaces an existing tag.<\/p>\n\n<h4>Free features<\/h4>\n\n<ul>\n<li>Guided Google Analytics connection and property and website data-stream selection.<\/li>\n<li>Analytics overview, daily traffic trend, and top-five content reports.<\/li>\n<li>An inclusive last-7-days range, with one dated trend point per day. Free rejects longer ranges on the server.<\/li>\n<li>Persistent managed Google connection, plus an advanced self-managed OAuth option.<\/li>\n<li>Plugin-managed, externally managed, or disabled tag installation modes.<\/li>\n<li><code>GT-<\/code>, <code>G-<\/code>, <code>AW-<\/code>, and <code>DC-<\/code> identifiers through gtag.js.<\/li>\n<li>Official Google Tag Manager head and body snippets for <code>GTM-<\/code> identifiers.<\/li>\n<li>Existing legacy <code>UA-<\/code> tracking IDs remain visible and continue rendering, including when Google routes the installed tag to a connected GA4 destination.<\/li>\n<li>Multiple Google tag destinations and optional Consent Mode v2 denied defaults.<\/li>\n<li>Backward compatibility for existing trusted custom gtag commands.<\/li>\n<\/ul>\n\n<p>Settings are available under <strong>Settings &gt; WP Global Site Tag<\/strong>. The <strong>Analytics dashboard<\/strong> tab contains the recommended connection route. The <strong>Tracking settings<\/strong> tab preserves the manual route.<\/p>\n\n<h4>Recommended Google connection<\/h4>\n\n<p>Click <strong>Connect with Google<\/strong>, choose an account, approve read-only Analytics access, and return to WordPress to choose a property and website data stream. The recommended connection uses the Digital Apps connection service so administrators do not need to create a Google Cloud project or handle OAuth credentials.<\/p>\n\n<p>Digital Apps exchanges the authorization code and retains the Google refresh token while the connection is active. WordPress stores an encrypted opaque connection token and short-lived Google access tokens. The plugin then calls the Google Analytics Admin and Data APIs directly, so Analytics property, stream, and report requests and responses do not pass through Digital Apps.<\/p>\n\n<p>Because Digital Apps retains the refresh token, it is technically able to request Analytics access while the connection remains active. The advanced self-managed route below is available for administrators who do not accept that trust boundary.<\/p>\n\n<p>Administrators who require no Digital Apps token custody can open <strong>Advanced: use your own Google OAuth application<\/strong>. That route provides the Google Cloud instructions and exact callback URL. Credentials may be saved encrypted or defined in <code>wp-config.php<\/code> as <code>WP_GLOBAL_SITE_TAG_GOOGLE_CLIENT_ID<\/code> and <code>WP_GLOBAL_SITE_TAG_GOOGLE_CLIENT_SECRET<\/code>. Constants take precedence.<\/p>\n\n<p>After Google returns to WordPress, choose an Analytics property and its website data stream. The plugin recommends hostname and exact existing-Measurement-ID matches, but an administrator confirms every selection.<\/p>\n\n<h4>Identifier guide<\/h4>\n\n<ul>\n<li><strong>Property ID<\/strong> is the numeric GA4 reporting property used by the Data API.<\/li>\n<li><strong>Data Stream ID<\/strong> is the numeric identifier of one stream inside a property.<\/li>\n<li><strong>Measurement ID<\/strong> begins with <code>G-<\/code> and identifies the website tag for that stream.<\/li>\n<li><strong>Google Tag Manager container ID<\/strong> begins with <code>GTM-<\/code> and is a separate tracking integration.<\/li>\n<li>A legacy <strong>Universal Analytics tracking ID<\/strong> begins with <code>UA-<\/code>. Version 2 preserves it as the frontend tag but does not use it as the GA4 reporting Measurement ID.<\/li>\n<\/ul>\n\n<p>These values are stored separately. Choosing a reporting stream does not overwrite the generic tracking ID unless the administrator explicitly chooses replacement after a mismatch warning.<\/p>\n\n<h4>Installation modes<\/h4>\n\n<ul>\n<li><strong>Install with WP Global Site Tag<\/strong> lets this plugin output the saved tag.<\/li>\n<li><strong>Tracking is installed elsewhere<\/strong> keeps reporting available but prevents duplicate tag output.<\/li>\n<li><strong>Do not install a tag<\/strong> disables tag output while preserving the reporting connection.<\/li>\n<\/ul>\n\n<h4>Existing users<\/h4>\n\n<p>Version 2 preserves the existing option name, manual tag ID, additional destinations, Consent Mode setting, trusted custom commands, hooks, and frontend behavior. This includes legacy <code>UA-<\/code> identifiers that Google may route to a connected GA4 destination. Existing sites default to plugin-managed installation so an update does not stop measurement. Analytics reporting remains disconnected until an administrator completes the new read-only connection.<\/p>\n\n<h4>Consent and privacy<\/h4>\n\n<p>Consent Mode is not a consent banner. You still need a consent management platform or your own consent interface to collect a visitor's choice and update Google's consent state.<\/p>\n\n<p>When Consent Mode defaults are enabled, this plugin still loads gtag.js. Google may receive consent-state and cookieless requests before consent is granted. If your requirements prohibit loading Google before consent, use the <code>wp_global_site_tag_should_render<\/code> filter to prevent output until your consent system allows it.<\/p>\n\n<p>When using a GTM container, configure consent initialization and defaults inside Google Tag Manager. The plugin's Consent Mode setting applies only to gtag.js output.<\/p>\n\n<p>With the recommended connection, Digital Apps stores the Google refresh token and WordPress stores an opaque connection token and short-lived access tokens. With the advanced self-managed connection, OAuth credentials and Google refresh and access tokens stay on WordPress. Locally stored connection data is encrypted with keys derived from WordPress salts and saved in non-autoloaded options. Administrators can disconnect at any time, which requests revocation and removes local connection data and report caches. The saved frontend tag remains unchanged.<\/p>\n\n<h4>External services<\/h4>\n\n<p>When tracking is enabled, visitors' browsers request Google tag resources from <code>https:\/\/www.googletagmanager.com<\/code>. These requests disclose standard web request information such as the visitor's IP address, browser details, and referring page to Google. Configured Google products may send additional measurement or advertising events.<\/p>\n\n<p>The recommended connection sends the site URL, hostname, plugin and protocol versions, callback URL, a short-lived state and code challenge, and later an opaque connection token to <code>https:\/\/connect.digitalapps.com\/v1\/<\/code>. Digital Apps uses this information only to complete Google authorization, retain the refresh token, renew short-lived access, and revoke the connection. It does not receive Analytics property, stream, or report requests or responses.<\/p>\n\n<p>When an administrator views reports, the plugin communicates directly with these Google services:<\/p>\n\n<ul>\n<li>Google authorization at <code>accounts.google.com<\/code>.<\/li>\n<li>Google Analytics Admin API at <code>analyticsadmin.googleapis.com<\/code>.<\/li>\n<li>Google Analytics Data API at <code>analyticsdata.googleapis.com<\/code>.<\/li>\n<\/ul>\n\n<p>The advanced self-managed route additionally communicates directly with Google token and revocation services at <code>oauth2.googleapis.com<\/code>.<\/p>\n\n<p>The plugin requests the <code>analytics.readonly<\/code> scope. Google receives the administrator's authorization request and normal request metadata. Reporting requests include the selected property, date range, and allowlisted report fields. The plugin does not add telemetry. Review the <a href=\"https:\/\/digitalapps.com\/privacy-policy\/\">Digital Apps Privacy Policy<\/a> and <a href=\"https:\/\/digitalapps.com\/terms-and-conditions\/\">Terms<\/a>.<\/p>\n\n<p>Review Google's <a href=\"https:\/\/policies.google.com\/privacy\">Privacy Policy<\/a>, <a href=\"https:\/\/policies.google.com\/terms\">Terms of Service<\/a>, <a href=\"https:\/\/developers.google.com\/terms\/api-services-user-data-policy\">OAuth terms<\/a>, and <a href=\"https:\/\/marketingplatform.google.com\/about\/analytics\/terms\/\">Google Analytics terms<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>wp-global-site-tag<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the plugin through WordPress.<\/li>\n<li>Activate <strong>WP Global Site Tag<\/strong>.<\/li>\n<li>Open <strong>Settings &gt; WP Global Site Tag<\/strong>.<\/li>\n<li>For reports, click <strong>Connect with Google<\/strong>, choose an account, property, and website data stream.<\/li>\n<li>For manual tracking only, open Tracking settings, enter a valid tag or container ID, choose the installation mode, and save.<\/li>\n<li>Verify public tag behavior with Google's Tag Assistant and verify your consent workflow.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20i%20keep%20my%20existing%20manually%20configured%20tag%3F\"><h3>Can I keep my existing manually configured tag?<\/h3><\/dt>\n<dd><p>Yes. Version 2 preserves it. The Analytics setup looks for an exact stream Measurement ID match and asks before making any change. If the saved value is a legacy <code>UA-<\/code> identifier, confirm current collection in GA4 Realtime before replacing or removing it.<\/p><\/dd>\n<dt id=\"why%20do%20reports%20need%20a%20google%20connection%20when%20tracking%20already%20works%3F\"><h3>Why do reports need a Google connection when tracking already works?<\/h3><\/dt>\n<dd><p>Tracking sends data from the public site. Reporting requires separate read-only permission to retrieve data from a GA4 property. A manual tag alone does not grant report access.<\/p><\/dd>\n<dt id=\"do%20i%20need%20to%20create%20a%20google%20cloud%20oauth%20application%3F\"><h3>Do I need to create a Google Cloud OAuth application?<\/h3><\/dt>\n<dd><p>No for the recommended connection. Digital Apps owns the OAuth application and required API configuration. Create your own application only when using the advanced self-managed route.<\/p><\/dd>\n<dt id=\"how%20do%20i%20fix%20redirect_uri_mismatch%20with%20my%20own%20oauth%20application%3F\"><h3>How do I fix redirect_uri_mismatch with my own OAuth application?<\/h3><\/dt>\n<dd><p>Open the advanced connection section, copy its callback URL, and add that exact value to your OAuth client's authorized redirect URIs. Check scheme, host, path, and trailing slash exactly.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20google%20access%20is%20revoked%3F\"><h3>What happens when Google access is revoked?<\/h3><\/dt>\n<dd><p>The dashboard asks an administrator to reconnect. Tracking remains in its selected installation mode and the saved tag is not removed.<\/p><\/dd>\n<dt id=\"why%20is%20a%20property%20or%20stream%20missing%3F\"><h3>Why is a property or stream missing?<\/h3><\/dt>\n<dd><p>Confirm the connected Google account can access the GA4 property, both required APIs are enabled, and the property has a Web data stream. Mobile-app streams are not offered as website choices.<\/p><\/dd>\n<dt id=\"why%20is%20cached%20data%20shown%3F\"><h3>Why is cached data shown?<\/h3><\/dt>\n<dd><p>During a temporary Google outage or rate limit, the dashboard may show its most recent cached report with a clear stale-data notice. Use Refresh after Google is available again.<\/p><\/dd>\n<dt id=\"can%20free%20show%20more%20than%207%20days%3F\"><h3>Can Free show more than 7 days?<\/h3><\/dt>\n<dd><p>No. Free provides an inclusive 7-day report. The separately installed Pro add-on adds 30-day, longer, and custom ranges.<\/p><\/dd>\n<dt id=\"does%20enabling%20consent%20mode%20block%20google%20until%20consent%3F\"><h3>Does enabling Consent Mode block Google until consent?<\/h3><\/dt>\n<dd><p>No. It queues denied defaults before Google tag configuration, but gtag.js is still requested. Connect a consent management platform that calls <code>gtag('consent', 'update', ...)<\/code>, or prevent rendering with the provided filter until loading is allowed.<\/p><\/dd>\n<dt id=\"how%20do%20i%20prevent%20tag%20output%20for%20selected%20requests%3F\"><h3>How do I prevent tag output for selected requests?<\/h3><\/dt>\n<dd><p>Choose an external or disabled installation mode, or return <code>false<\/code> from the <code>wp_global_site_tag_should_render<\/code> filter. The filter receives the current decision, normalized identifier, and normalized plugin options.<\/p><\/dd>\n<dt id=\"what%20does%20uninstall%20remove%3F\"><h3>What does uninstall remove?<\/h3><\/dt>\n<dd><p>Uninstall removes plugin settings, encrypted Google credentials and tokens, OAuth state, and registered report caches, including across multisite. Define <code>WP_GLOBAL_SITE_TAG_PRESERVE_DATA<\/code> as <code>true<\/code> before uninstalling to retain data.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Added a persistent Connect with Google flow, advanced self-managed OAuth, property selection, and website data-stream setup.<\/li>\n<li>Added Free overview, trend, and top-content reports for an inclusive 7-day range.<\/li>\n<li>Added encrypted local connection storage, optional self-managed credentials, safe token refresh and revocation, fixed-host Google API adapters, caching, stale fallback, and refresh controls.<\/li>\n<li>Added explicit plugin-managed, externally managed, and disabled installation modes without changing existing tracking on upgrade.<\/li>\n<li>Preserved legacy <code>UA-<\/code> tracking IDs during upgrades and added guidance for connected GA4 destinations.<\/li>\n<li>Added centralized entitlements and extension points for the separate Pro add-on.<\/li>\n<li>Added responsive, keyboard-accessible setup and dashboard interfaces with live status announcements.<\/li>\n<li>Expanded privacy, external-service, troubleshooting, uninstall, developer, test, and release documentation.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added correct, separate rendering for Google tags and GTM containers.<\/li>\n<li>Added structured multiple destinations and Consent Mode v2 defaults.<\/li>\n<li>Restricted custom JavaScript editing to trusted users and blocked script-tag breakout content.<\/li>\n<li>Fixed missing-option warnings, incomplete saves, duplicate configuration, escaping, accessibility, and translation issues.<\/li>\n<li>Added complete uninstall cleanup, including multisite support and an opt-out constant.<\/li>\n<li>Replaced legacy Docker, Gulp, and Webpack tooling with wp-env and smoke tests.<\/li>\n<\/ul>\n\n<h4>1.0.7<\/h4>\n\n<ul>\n<li>Removed warning messages.<\/li>\n<\/ul>\n\n<h4>1.0.6<\/h4>\n\n<ul>\n<li>Added MIME type metadata.<\/li>\n<\/ul>\n\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Updated the settings label.<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Added a settings link on the Plugins screen.<\/li>\n<li>Moved the settings page under Settings.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Updated compatibility metadata for WordPress 5.0.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Install a Google tag and view useful Google Analytics 4 reports inside WordPress with a guided, read-only connection.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/79023","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=79023"}],"author":[{"embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/digitalapps"}],"wp:attachment":[{"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=79023"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=79023"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=79023"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=79023"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=79023"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=79023"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}