BACK TO DIRECTORY

GOOSEC

by goosec

0.0
(0 ratings)

GOOSEC collects the external resources (script, link, iframe, img) that your pages load, and lists them in one place. It tells you when a new destination appears, and when the structure of your front page changes.

Tag managers, ads, analytics, payment services — most sites load scripts that the site owner never explicitly reviewed. Knowing what is actually loaded today is the starting point.

What it does

  • Lists external destinations — Extracts script, link, iframe and img sources from the HTML of your pages. You can scan several pages, and sites behind HTTP Basic authentication are supported.
  • Marks what is new — Compares against the previous scan and flags destinations that appear for the first time.
  • Shows a three-level risk hint — Domains in the plugin’s built-in trust list (73 entries) or in your own list are shown as low. Direct requests to IP addresses, free top-level domains and URL shorteners are shown as high. Everything else is shown as unverified.
  • Detects front page tampering — Compares the tag structure, the resources it loads and the contents of inline scripts against a baseline you approve. Editing article text does not trigger a notification.
  • Sends email — Notifies you about new destinations, high-risk destinations and structural changes. The same state is never reported twice.
  • Runs daily — One scheduled scan per day, plus a manual scan button.
  • Keeps history — Scan history is kept for 365 days; a daily job removes anything older.

About the risk levels

High, unverified and low are a hint about what to look at first, not a verdict about safety. They are decided from the shape of the domain and from whether it appears in a trust list. The plugin does not inspect the content of any request. A destination shown as low is not guaranteed to be safe.

The 73 built-in entries can be reviewed in full on the settings screen. You cannot edit that list, but you can add your own domains, and the reason column tells you which list a domain matched.

What it cannot see

The plugin fetches the HTML of your pages from the server and parses it. Requests that only appear while a visitor’s browser is running the page — for example scripts injected through a tag manager — are not visible this way. If you need those, see the optional paid service below.

Optional paid service

Everything described above works on its own and contacts no third-party service.

If you subscribe to GOOSEC Lite, you can upload the configuration file we issue, and the plugin will show detections made in your visitors’ browsers. This is entirely optional. No request leaves your site until you upload that file. The destinations and the data involved are listed under “External services” below.

See https://www.goosec.site/ for details.

External services

With the free features only, this plugin does not connect to any third-party service. Everything it collects is stored in your own WordPress database. It does fetch your own pages over HTTP in order to scan them.

Note for reviewers: includes/class-risk.php contains a static list of domain names (Google, CDNs, payment providers and so on). It is a classification allow-list compared as plain strings against URLs found while scanning the site owner’s own pages. The plugin never connects to, enqueues or loads anything from those domains.

If you subscribe to GOOSEC Lite and upload goosec_config.js from the settings screen, the plugin connects to the following services.

1. GOOSEC API (api.goosec.jp) — retrieving detections

  • Sent: the license key, scenario ID and read key issued when you subscribe, plus the date range being requested.
  • Not sent: your site’s content, your posts, or any personal data about your visitors.
  • When: when an administrator opens the plugin dashboard, and once per day in the background.

2. GOOSEC detection script (your own subdomain of goosec.jp, and assets.goosec.jp)

  • Once enabled, a script tag is added to every page of your site.
  • Your visitors’ browsers send information about outbound requests occurring on the page (destination URL, page URL, timestamp) to GOOSEC servers.
  • This is part of the subscribed service and requires a paid plan.

All of the above services are operated by GIV Inc., the author of this plugin. A paid subscription is required; no data is sent unless you subscribe and upload goosec_config.js yourself.

  • Service provider: GIV Inc. (https://www.giv.co.jp/)
  • Service site: https://www.goosec.site/
  • Terms of service: https://www.goosec.site/terms
  • Privacy policy: https://www.goosec.site/privacy

Screenshots

Dashboard — how many external destinations were found, the risk breakdown, and the state of front page tampering detection

Dashboard — how many external destinations were found, the risk breakdown, and the state of front page tampering detection

Destination list — domain, type, risk, the reason for that level, and the URL. Newly appeared destinations are marked NEW

Destination list — domain, type, risk, the reason for that level, and the URL. Newly appeared destinations are marked NEW

Scan history — past scans in chronological order

Scan history — past scans in chronological order

Settings — pages to scan, HTTP Basic authentication, and front page tampering detection

Settings — pages to scan, HTTP Basic authentication, and front page tampering detection

Trusted domains — the 73 built-in entries can be reviewed in full on the settings screen

Trusted domains — the 73 built-in entries can be reviewed in full on the settings screen

Plugin Details

Active Installs
0
Total Downloads
23
Version
1.5.5
Requires WP
5.8
Requires PHP
7.4
Tested Up To
7.1
Added
2026-09-17
Last Updated
2026-09-17 5:24am GMT

Ratings

5
0
4
0
3
0
2
0
1
0