• About
    • History of Dallas SEO
  • Contact
  • Topics
    • Bing
    • Blogging
    • Branding
    • Domain Names
    • Google
    • Internet Marketing
    • Link Building
    • Local Search
    • Marketing
    • Public Relations
    • Reputation Management
    • Search Engine Marketing
    • Search Engine Optimization
    • Search Engines
    • Social Media
    • Tech
  • Advertise
  • Services
    • Search Engine Optimization
    • Ongoing SEO Services
    • SEO Expert Witness
    • Google Penalty Recovery
    • Mini SEO Audit
    • Link Audit
    • Keyword Research
    • Combine Websites SEO Services
    • PPC Management
    • Online Reputation Management
    • Domain Name Consultant
    • Domain Names & Expired Domains
    • Domain Name Appraisal

Bill Hartzer

GoDaddy Airo: Register your .com domain name today!
Home » Google » Google Site Kit Gives Attackers Access to Google Search Console

Google Site Kit Gives Attackers Access to Google Search Console

Posted on May 13, 2020 Written by Bill Hartzer

Site Kit by Google vulnerability

Not long ago, I installed the Google Site Kit WordPress plugin, as it is an official Google WordPress plugin. When you install the plugin, it gives you an easier way to view data from Google Analytics, Google Search Console, Google AdSense, and Google PageSpeed Insights. You can view this data for the entire site or you can view it per page or per post. It doesn’t really do anything special except make it easier for you to view the data. You can see it directly in the WordPress dashboard rather than having to go to each of those sites separately: Google Analytics, Google Search Console, Google AdSense, and Google PageSpeed Insights. Well, there’s a problem with the plugin: an attacker can gain access to your Google Search Console for the site, and presumably with access they could do some harm.

In this case, they have to be an authenticated user of the WordPress site. If they’re a WordPress user of the site, they could potentially get access to the Google Search Console if they didn’t already have that access.

Wordfence has discovered a vulnerability in the Google Site Kit WordPress Plugin. They recommend updating the plugin as soon as possible. Logging into a WordPress site (such as this one) where I had Google Site Kit installed, there is an update for the plugin. However, rather than updating it I chose to simply deactivate the plugin and then delete it.

Here’s what they found:
“In order to establish the first connection with Site Kit and Google Search Console, the plugin generates a proxySetupURL that is used to redirect a site’s administrator to Google OAuth and run the site owner verification process through a proxy.” They went on to explain that “Due to the lack of capability checks on the admin_enqueue_scripts action, the proxySetupURL was displayed as part of the HTML source code of admin pages to any authenticated user accessing the /wp-admin dashboard.” They have to be an authenticated user of the WordPress site in order to see the code. That is my understanding.

Do You Need Google Site Kit?

I really haven’t seen any additional benefits from having the Google Site Kit WordPress plugin installed, as it does not give me any more functionality in my blog. It’s not helpful for users at all, just an add-on to the WordPress dashboard. If I need the data, then I can just go log into Google Analytics, Google Search Console, Google AdSense, or Google PageSpeed Insights. Also, adding more plugins that aren’t really necessary can help speed up the overall performance of the site, as it doesn’t have to load if the plugin isn’t installed. I’m personally a big fan of removing all plugins that are not needed, as it will help the site load faster, and the site is less vulnerable to security issues (as we can see with this Google Site Kit plugin).

My recommendation? Only install Google Site Kit if you absolutely can’t live without it. And here’s a hint: you don’t really need it.

Filed Under: Google

About Bill Hartzer

Bill Hartzer is the CEO of Hartzer Consulting and founder of DNAccess, a domain name protection and recovery service. A recognized authority in digital marketing and domain strategy, Bill is frequently called upon as an Expert Witness in internet-related legal cases. He's been sharing insights and research here on BillHartzer.com for over two decades.

Bill Hartzer on Search, Marketing, Tech, and Domains.

Recent Posts

  • Why Everyone on Google Trends Is Suddenly a Person—And What It Means for SEO July 14, 2025
  • Grow Your Instagram Like a Pro with Hexrate’s Game-Changing Tools July 14, 2025
  • Unbounce Doubles Down on AI and Automation to Boost Go-To-Market Teams July 10, 2025
  • NameSilo to Acquire SewerVUE Technology in $2.45M Deal July 10, 2025
  • Internet Marketing Ninjas Acquired by Previsible.IO July 9, 2025
  • Metricool Brings Real Analytics to Personal LinkedIn Profiles July 8, 2025
  • This Cleveland Agency Found a Smarter Way to Rank in Every Suburb—Without Opening More Offices July 8, 2025
  • Survey: Gen Z Reuses Passwords but Demands Bank-Level Security From Small Businesses July 8, 2025
  • Liftoff Reveals What’s Actually Working in Mobile Ads July 7, 2025
  • EasySend’s Big Move: AI Tools That Make Static Forms Obsolete July 7, 2025
  • Is Social Media Failing Small Businesses? New Survey Reveals a Hidden Blind Spot July 7, 2025
  • Why Cloudflare’s Pay Per Crawl Is a Trap for 99% of Websites July 2, 2025
  • The Hidden Risk of Double Letters in Brand and Domain Names July 2, 2025
  • GEO Verified™ Launches to Help Brands Survive the AI Search Shakeup July 1, 2025
  • RetailOnline.com Hits the Market After 25 Years—And It’s Built for the Future of E-Commerce July 1, 2025
  • AI-Powered Task Planning: The Future of Business Efficiency and Personal Productivity June 30, 2025
  • New Yoast Add-On Turns Google Docs Into an SEO Power Tool June 26, 2025
  • Simon Data Flips the Script on Marketing with AI Agents June 26, 2025
  • IAB Lays Down the Law for Gaming Ads—Here’s What Brands Need to Know June 26, 2025
  • Google Review Extortion Text Message – Scam Warning for Business Owners June 25, 2025

Hartzer Domains

Bare-Metal Servers by HostDime

DFWSEM logo

Bill Hartzer is a Brand Ambassador for:

Industry Friends

I Love SEO
WTFSEO
SEO By the Sea
Brian Harnish
Jeff Lenney
Jeff Gabriel
Scott Hendison
Dixon Jones
Brian Hartzer
Navah Hopkins
DNAccess
SEO Dallas
Confirmed Stolen

Connect With Bill Hartzer

Bill Hartzer on Twitter
Bill Hartzer on BlueSky
Bill Hartzer on Instagram
Hartzer Consulting on Facebook
Bill Hartzer on Facebook
Bill Hartzer on YouTube

Categories

  • Advertising (109)
  • AI (201)
  • Bing Search Engine (8)
  • Blogging (43)
  • Branding (19)
  • Domain Names (316)
  • Google (261)
  • Internet Marketing (52)
  • Internet Usage (95)
  • Link Building (53)
  • Local Search (63)
  • Marketing (232)
  • Marketing Foo (34)
  • Pay Per Click (9)
  • Podcast (19)
  • Public Relations (9)
  • Reputation Management (14)
  • Search Engine Marketing (46)
  • Search Engine Marketing Events (60)
  • Search Engine Marketing Firms (94)
  • Search Engine Marketing Jobs (33)
  • Search Engine Optimization (189)
  • Search Engines (223)
  • Social Media (302)
  • Social Media Marketing (59)
  • Tech (16)
  • Web Analytics (21)
  • Webinars (1)

Note: All product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only, and are mentioned only to help my readers. All other trademarks cited herein are the property of their respective owners. Use of these names, logos, and brands does not imply endorsement.

 

Hartzer Consulting

Website, Content, and Marketing by Hartzer Consulting, LLC.

Disclaimer - Privacy Policy - Terms of Use

Copyright © 2025 ·