GOOSEC collects the external resources (script, link, iframe, img) that your pages load, and lists them in one place. It tells you when a new destination appears, and when the structure of your front page changes.
Tag managers, ads, analytics, payment services — most sites load scripts that the site owner never explicitly reviewed. Knowing what is actually loaded today is the starting point.
script, link, iframe and img sources from the HTML of your pages. You can scan several pages, and sites behind HTTP Basic authentication are supported.High, unverified and low are a hint about what to look at first, not a verdict about safety. They are decided from the shape of the domain and from whether it appears in a trust list. The plugin does not inspect the content of any request. A destination shown as low is not guaranteed to be safe.
The 73 built-in entries can be reviewed in full on the settings screen. You cannot edit that list, but you can add your own domains, and the reason column tells you which list a domain matched.
The plugin fetches the HTML of your pages from the server and parses it. Requests that only appear while a visitor’s browser is running the page — for example scripts injected through a tag manager — are not visible this way. If you need those, see the optional paid service below.
Everything described above works on its own and contacts no third-party service.
If you subscribe to GOOSEC Lite, you can upload the configuration file we issue, and the plugin will show detections made in your visitors’ browsers. This is entirely optional. No request leaves your site until you upload that file. The destinations and the data involved are listed under “External services” below.
See https://www.goosec.site/ for details.
With the free features only, this plugin does not connect to any third-party service. Everything it collects is stored in your own WordPress database. It does fetch your own pages over HTTP in order to scan them.
Note for reviewers: includes/class-risk.php contains a static list of domain names (Google, CDNs, payment providers and so on). It is a classification allow-list compared as plain strings against URLs found while scanning the site owner’s own pages. The plugin never connects to, enqueues or loads anything from those domains.
If you subscribe to GOOSEC Lite and upload goosec_config.js from the settings screen, the plugin connects to the following services.
1. GOOSEC API (api.goosec.jp) — retrieving detections
2. GOOSEC detection script (your own subdomain of goosec.jp, and assets.goosec.jp)
All of the above services are operated by GIV Inc., the author of this plugin. A paid subscription is required; no data is sent unless you subscribe and upload goosec_config.js yourself.