GSheetConnector for Forminator Forms Security & Risk Analysis

wordpress.org/plugins/gsheetconnector-forminator

Send your Forminator Forms data directly to your Google Sheet in a real-time.

1K active installs v1.0.17 PHP 7.4+ WP 5.6+ Updated Jan 2, 2026
forminatorforminator-forms-google-sheetforminator-google-sheetgoogle-sheet-forminatorwordpress-google-sheet
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 14, 2025
Safety Verdict

Is GSheetConnector for Forminator Forms Safe to Use in 2026?

Generally Safe

Score 99/100

GSheetConnector for Forminator Forms has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 14, 2025Updated 3mo ago
Risk Assessment

The gsheetconnector-forminator plugin, version 1.0.17, demonstrates a generally strong security posture with several positive indicators. Notably, all identified AJAX entry points have authentication checks, and 100% of SQL queries utilize prepared statements, which significantly mitigates SQL injection risks. The plugin also implements a robust number of nonce and capability checks, further enhancing its defenses. However, the presence of the 'unserialize' function is a notable concern. While not directly flagged as a critical vulnerability in the taint analysis, 'unserialize' is inherently risky and can lead to serious security issues if not handled with extreme care and proper input validation, especially when dealing with user-supplied data. The taint analysis did reveal one flow with unsanitized paths, indicating a potential for path traversal or similar vulnerabilities, although it was not classified as critical. The plugin's vulnerability history shows a single medium-severity CVE related to Cross-Site Scripting, which was patched. The absence of currently unpatched vulnerabilities is positive, but the past XSS issue highlights the importance of vigilant output escaping and sanitization.

Key Concerns

  • Dangerous function 'unserialize' detected
  • Taint flow with unsanitized paths
  • Past medium severity XSS vulnerability
Vulnerabilities
1

GSheetConnector for Forminator Forms Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22752medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

GSheetConnector for Forminator Forms <= 1.0.12 - Reflected Cross-Site Scripting

Jan 14, 2025 Patched in 1.0.13 (50d)
Code Analysis
Analyzed Mar 16, 2026

GSheetConnector for Forminator Forms Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
12 prepared
Unescaped Output
73
448 escaped
Nonce Checks
16
Capability Checks
6
File Operations
3
External Requests
1
Bundled Libraries
2

Dangerous Functions Found

unserialize$meta_array = unserialize($meta_value);includes\class-gs-formntr-services.php:182
unserialize$meta_value = unserialize($feed['meta_value']);includes\pages\edit-sheet.php:63

Bundled Libraries

GuzzleFreemius1.0

SQL Query Safety

100% prepared12 total queries

Output Escaping

86% escaped521 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

7 flows1 with unsanitized paths
verify_gs_formntr_integation (includes\class-gs-formntr-processes.php:53)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GSheetConnector for Forminator Forms Attack Surface

Entry Points12
Unprotected0

AJAX Handlers 12

authwp_ajax_formntr_gs_set_auth_expired_adds_intervalincludes\class-gs-formntr-adds.php:32
authwp_ajax_formntr_gs_close_auth_expired_adds_intervalincludes\class-gs-formntr-adds.php:35
authwp_ajax_verify_gs_formntr_integationincludes\class-gs-formntr-processes.php:29
authwp_ajax_deactivate_gs_formntr_integationincludes\class-gs-formntr-processes.php:32
authwp_ajax_gs_formntr_clear_logsincludes\class-gs-formntr-processes.php:35
authwp_ajax_frm_clear_debug_logsincludes\class-gs-formntr-processes.php:38
authwp_ajax_sync_formntr_google_accountincludes\class-gs-formntr-processes.php:41
authwp_ajax_get_tab_listincludes\class-gs-formntr-processes.php:44
authwp_ajax_delete_feed_forminatorincludes\class-gs-formntr-services.php:40
authwp_ajax_gs_ff_install_pluginincludes\pages\extensions\gs-Formntr-extension-service.php:30
authwp_ajax_gs_ff_activate_pluginincludes\pages\extensions\gs-Formntr-extension-service.php:33
authwp_ajax_gs_ff_deactivate_pluginincludes\pages\extensions\gs-Formntr-extension-service.php:36
WordPress Hooks 21
filterconnect_message_on_updategsheetconnector-forminator.php:90
actionadmin_initgsheetconnector-forminator.php:145
actionadmin_initgsheetconnector-forminator.php:148
actionadmin_menugsheetconnector-forminator.php:151
actioninitgsheetconnector-forminator.php:154
actioninitgsheetconnector-forminator.php:157
actionwp_dashboard_setupgsheetconnector-forminator.php:163
actionadmin_noticesgsheetconnector-forminator.php:255
actionnetwork_admin_noticesgsheetconnector-forminator.php:256
actionadmin_print_stylesgsheetconnector-forminator.php:338
actionadmin_print_scriptsgsheetconnector-forminator.php:339
actionadmin_initincludes\class-gs-formntr-adds.php:29
actionadmin_noticesincludes\class-gs-formntr-adds.php:65
filterforminator_custom_form_submit_field_dataincludes\class-gs-formntr-services.php:43
actionadmin_initincludes\class-gs-formntr-services.php:46
actionadmin_initincludes\class-gs-formntr-services.php:49
actionadmin_noticesincludes\class-gs-formntr-services.php:342
actionadmin_noticesincludes\class-gs-formntr-services.php:436
actionadmin_noticesincludes\class-gs-formntr-services.php:444
actionadmin_noticesincludes\class-gs-formntr-services.php:447
filteradmin_footer_textincludes\pages\admin-footer.php:11

Scheduled Events 1

google_sheet_check_expiration
Maintenance & Trust

GSheetConnector for Forminator Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 2, 2026
PHP min version7.4
Downloads16K

Community Trust

Rating100/100
Number of ratings2
Active installs1K
Developer Profile

GSheetConnector for Forminator Forms Developer Profile

WesternDeal

11 plugins · 63K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
126 days
View full developer profile
Detection Fingerprints

How We Detect GSheetConnector for Forminator Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gsheetconnector-forminator/css/gs-formntr-free.css/wp-content/plugins/gsheetconnector-forminator/css/style.css/wp-content/plugins/gsheetconnector-forminator/js/gs-formntr-free.js/wp-content/plugins/gsheetconnector-forminator/js/gsheetconnector-forminator.js/wp-content/plugins/gsheetconnector-forminator/js/forminator/forminator.js/wp-content/plugins/gsheetconnector-forminator/js/forminator/forminator-form-builder.js/wp-content/plugins/gsheetconnector-forminator/js/forminator/forminator-form-preview.js/wp-content/plugins/gsheetconnector-forminator/js/forminator/forminator-form-steps.js+3 more
Script Paths
/wp-content/plugins/gsheetconnector-forminator/js/gs-formntr-free.js/wp-content/plugins/gsheetconnector-forminator/js/gsheetconnector-forminator.js/wp-content/plugins/gsheetconnector-forminator/js/forminator/forminator.js/wp-content/plugins/gsheetconnector-forminator/js/forminator/forminator-form-builder.js/wp-content/plugins/gsheetconnector-forminator/js/forminator/forminator-form-preview.js/wp-content/plugins/gsheetconnector-forminator/js/forminator/forminator-form-steps.js+3 more
Version Parameters
gsheetconnector-forminator/css/gs-formntr-free.css?ver=gsheetconnector-forminator/css/style.css?ver=gsheetconnector-forminator/js/gs-formntr-free.js?ver=gsheetconnector-forminator/js/gsheetconnector-forminator.js?ver=gsheetconnector-forminator/js/forminator/forminator.js?ver=gsheetconnector-forminator/js/forminator/forminator-form-builder.js?ver=gsheetconnector-forminator/js/forminator/forminator-form-preview.js?ver=gsheetconnector-forminator/js/forminator/forminator-form-steps.js?ver=gsheetconnector-forminator/js/forminator/forminator-form-validation.js?ver=gsheetconnector-forminator/js/forminator/forminator-fields.js?ver=gsheetconnector-forminator/js/forminator/forminator-ajax.js?ver=

HTML / DOM Fingerprints

CSS Classes
gsheetconnector-forminator-dashboard-widget
HTML Comments
freemiusCustomizing the Opt Message FreemiusEnd Customizing the Opt Message Freemiusfreemius
Data Attributes
gsheetconnector-forminator
JS Globals
gfff_fs
FAQ

Frequently Asked Questions about GSheetConnector for Forminator Forms