GOOSEC
by goosec 1 (0 reviews)

GOOSEC

Lists the external scripts loaded by your pages and tells you when a new destination appears.

GOOSEC ranks #61,726 among WordPress.org plugins with 1+ active installations, is #6,784 of 12,548 in the E-commerce category, a 1/5 rating from 0 reviews, and was last updated Sep 17, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1
v1.5.5 Current Version v1.5.5
Updated 6 days ago Last Update on 17 Sep, 2026
Refreshed 8 hours ago Last Refreshed on
#6,784 of 12,548 in E-commerce Actively maintained
View on WordPress.org
Rank
#61,726
No change
Active Installs
1+
-1%
KW Avg Position
N/A
No change
Downloads
56
+2 today
Support Resolved
0%
No change
Rating
20%
Review 1 out of 5
1 (0 reviews)

Next Milestone 10

Total Progress 20%
0+ 10+
60,780
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 8 more installs to reach 10+

Rank Changes

46,628 50,895 55,162 59,428 63,695 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
46,628 50,895 55,162 59,428 63,695 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Current #61,726
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 20 30 40 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
0 10 20 30 40 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

1.0
0 reviews
Overall 20%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about GOOSEC

Yes. Everything listed under "What it does" is free, and none of it contacts a third-party service.
They protect different layers. A WAF detects and blocks attacks against your server, such as SQL injection or XSS. A file integrity monitor detects changes to files on your server. This plugin lists the external destinations written into your pages and tells you when they change. Use them together.
No. The free scan runs in the background on the server, once a day, and does not affect page rendering for visitors. If you enable the optional paid detection, a script tag is added to every page.
First check whether it is a service you added yourself. If it is, add it to your trusted list. If you do not recognise it, look into the script that loads it. The level is decided from the shape of the domain alone, so high does not by itself mean the destination is malicious.
No. Low only means the domain is in the built-in trust list or in your own list. The plugin does not inspect what is being sent. Treat the levels as an order in which to look, nothing more. Front page tampering is reported when I simply update my site. Structural updates, such as adding a page or changing the design, are reported. Editing article text is not. After an intended change, press "Set the current state as the new baseline" on the dashboard. The same state is never reported twice.
Not with the free features. The plugin fetches your page's HTML from the server, and scripts that are added while the page runs in a browser do not appear in that HTML. If you need those, consider the paid plan.
Destinations and scan history are stored only in your own WordPress database. Nothing is sent anywhere else. The HTTP Basic authentication password, and the read key used by the paid plan, are stored encrypted using a key derived from your wp-config.php salts, and are never printed on screen. Note that anyone who can read wp-config.php can decrypt them; the purpose is to prevent them being read in plain text if the database contents alone are exposed.
Yes. Using Delete in WordPress removes the scan history tables, the settings and the uploaded configuration file. This cannot be undone. Deactivating does not remove anything, so use Deactivate if you only want to pause.
In wp-content/uploads/goosec/. It does not appear in the Media Library, because that list shows files registered as attachments and this file is not registered as one. Before 1.4.3 the file was stored inside the plugin folder, so updating the plugin could delete it. Updating to 1.4.3 or later moves an existing file to the new location automatically.

Sign In / Register

You need to sign in or register to use this feature.