shouldiuse.io

Categories

VERDICT

Should I use Site Kit by Google?

Site Kit is the one-stop solution for WordPress - sitekit.withgoogle.com

Worth it. WordPress site owners wanting free, official Google Analytics, Search Console, and AdSense dashboards in wp-admin should install it. Agencies, non-WordPress sites, and hardened security environments should not.

Confidence

Medium. Based on 20+ public sources; some 'Sitekit' results refer to an unrelated UK digital-health company.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

Site Kit

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • WordPress bloggers and small sites
  • Non-technical owners wanting Google dashboards
  • AdSense publishers
  • Basic GA4 + Search Console tracking

Not for

  • Agencies managing multiple client sites
  • Non-WordPress websites
  • Teams needing custom GTM-level tracking
  • Sites enforcing strict CSP or tight security

Gotchas - check before you buy

high

Metrics aren't shareable across client sites — agencies hit a wall

high

Update promptly — several XSS CVEs landed in 2025

medium

Site Kit data can differ significantly from raw GA4 reports

medium

Requires loosening CSP headers; conflicts with hardened setups

Pros and cons

Pros

  • Free, official Google plugin — no license cost
  • One-stop dashboards for Analytics, Search Console, AdSense, PageSpeed
  • Open source and actively maintained by Google
  • Helps earn money via built-in AdSense integration

Cons

  • Recurring stored-XSS vulnerabilities, multiple 2025 CVEs
  • Setup failures reported with no alternate connection path
  • Analytics numbers diverge from direct GA reports
  • Fails under strict CSP configurations
  • Weak fit for multi-client agency workflows

Sources & method

Analyzed 10/03/2026 - 10 sources - Active findings: several 2025 stored-XSS CVEs in the WordPress plugin — keep it updated.

official x2review x5security x3
  • CVE-2025-58229 — XSS, Cross-site scripting vulnerability in the Site Kit WordPress plugin.
  • CVE-2025-30776 — Stored XSS, Authenticated contributor+ stored cross-site scripting in Site Kit.
  • CVE-2025-50047 — Improper neutralization, Improper input neutralization recorded in NVD.
  • 2020 Search Console access flaw, Vulnerability granted attackers Search Console access; patched in 1.8.1.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 5/5. Free, official Google plugin
  • Ease of use: 3/5. Simple for basics; setup dead-ends reported
  • Feature depth: 3/5. Covers GA4, Search Console, AdSense; less flexible than GTM
  • Support quality: 2/5. Forum-based; users report unresolved connection failures
  • Security posture: 2/5. Repeated 2025 XSS CVEs despite Google backing
  • $0 Price Official free Google plugin
  • Yes Free tier All features included
  • 3 2025 CVEs Mostly stored-XSS, since patched
  • WordPress only Works with Open source: google/site-kit-wp

Pricing

Site Kit

Free

  • GA4, Search Console, AdSense, PageSpeed dashboards
  • WordPress conversion tracking
  • Official Google support forums

Security

Active findings: several 2025 stored-XSS CVEs in the WordPress plugin — keep it updated.

  • CVE-2025-58229 — XSSCross-site scripting vulnerability in the Site Kit WordPress plugin.⁵
  • CVE-2025-30776 — Stored XSSAuthenticated contributor+ stored cross-site scripting in Site Kit.
  • CVE-2025-50047 — Improper neutralizationImproper input neutralization recorded in NVD.
  • 2020 Search Console access flawVulnerability granted attackers Search Console access; patched in 1.8.1.³

Companies that use it

  • University of Illinois
Full analysis

Based on 20+ public sources; some 'Sitekit' results refer to an unrelated UK digital-health company.

Free official Google plugin for WordPress analytics — great for simple sites, wrong for agencies and strict setups.

Methodology

Based on 20+ public sources; some 'Sitekit' results refer to an unrelated UK digital-health company.

Sources

  1. official
  2. official
  3. security
  4. security
  5. CVE-2025-58229 — XSSsentinelone.com
    security
  6. review
  7. review
  8. review
  9. review
  10. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.