
Create Post by Google Document Security & Risk Analysis
wordpress.org/plugins/create-post-by-google-documentSync Google Docs with WordPress to create posts.
Is Create Post by Google Document Safe to Use in 2026?
Generally Safe
Score 100/100Create Post by Google Document has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'create-post-by-google-document' plugin v1.0.0 demonstrates a mixed security posture. On the positive side, it has a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed. Furthermore, all SQL queries are properly prepared, and external HTTP requests are present but not directly flagged as a risk in the provided data. The plugin also incorporates nonce checks and a reasonable percentage of output escaping, indicating some adherence to WordPress security best practices.
However, several concerns warrant attention. The presence of the 'unserialize' function is a significant red flag, as it can be a vector for remote code execution if used with untrusted input. While taint analysis shows no critical or high severity flows, the two identified flows with unsanitized paths coupled with the 'unserialize' function represent a potential risk, especially if these paths lead to the unserialization process. The lack of capability checks on any entry points, though the entry points are currently zero, means that if new entry points were introduced without proper authorization checks, it could create vulnerabilities.
With no recorded vulnerability history (CVEs), the plugin appears to have a clean past. This, combined with the limited attack surface and good SQL handling, suggests a developer who is aware of some security principles. Nevertheless, the 'unserialize' function and the presence of unsanitized paths, despite the current lack of exploitable taint flows, mean the plugin is not entirely risk-free. Diligence in code review and potential sanitization of inputs before 'unserialize' would be crucial.
Key Concerns
- Dangerous function: unserialize used
- Flows with unsanitized paths detected
- No capability checks on entry points
- Output escaping not fully implemented (21%)
Create Post by Google Document Security Vulnerabilities
Create Post by Google Document Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Create Post by Google Document Attack Surface
WordPress Hooks 3
Maintenance & Trust
Create Post by Google Document Maintenance & Trust
Maintenance Signals
Community Trust
Create Post by Google Document Alternatives
EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
embedpress
EmbedPress lets you embed videos, pages, social feeds, embed PDF 3D flipbooks & other content on WordPress without coding & enhance storytelling.
WP Responsive Recent Post Slider/Carousel
wp-responsive-recent-post-slider
Display Responsive Recent Post Slider and Carousel on your site with 4 designs (Slider) and 1 designs (Carousel) using shortcode and Gutenberg block.
Document Embedder Addons for Elementor – Embed Documents in Elementor Websites
document-embedder-addons-for-elementor
Document Embedder Addons for Elementor makes it simple to embed PDFs, Word docs, and others into your pages, no downloads or redirects needed.
Connector for Gravity Forms and Google Sheets
wp-gravity-forms-spreadsheets
Gravity Forms Google Sheets Connector sends Gravity forms entries to Google Sheets.
RV Embed PDF
rv-embed-pdf
Embeds a PDF in your page or post when you insert it with the Add Media button.
Create Post by Google Document Developer Profile
3 plugins · 50 total installs
How We Detect Create Post by Google Document
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/create-post-by-google-document/admin/css/cpbgd-post-by-google-document-admin.csscreate-post-by-google-document/admin/css/cpbgd-post-by-google-document-admin.css?ver=HTML / DOM Fingerprints
cpbgd-post-by-google-document-admin-cssdata-action="cpbgd_upload_doc"data-nonce="cpbgd_upload_doc_nonce"window.cpbgd_upload_doc_nonce