Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Security & Risk Analysis

wordpress.org/plugins/integration-for-contact-form-7-and-google-sheets

Send Contact Form 7, WPForms, Elementor, Ninja Forms, Contact Form Entries Plugin and many other contact form submissions to Google Sheets.

1K active installs v1.1.3 PHP 5.3+ WP 4.7+ Updated Dec 15, 2025
contact-form-7-google-sheetsgoogle-sheetsninja-forms-google-sheetswordpress-google-sheetswpforms-google-sheet-integration
94
A · Safe
CVEs total2
Unpatched0
Last CVEJul 18, 2025
Safety Verdict

Is Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Safe to Use in 2026?

Generally Safe

Score 94/100

Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jul 18, 2025Updated 3mo ago
Risk Assessment

The plugin 'integration-for-contact-form-7-and-google-sheets' v1.1.3 exhibits a mixed security posture. While it shows good practices in SQL query preparation (78%) and output escaping (85%), and a remarkably small attack surface with no apparent unprotected entry points from static analysis, significant concerns arise from its vulnerability history and taint analysis. The presence of two known CVEs, one critical and one medium, despite none being currently unpatched, suggests a pattern of past vulnerabilities that required significant remediation. The critical historical CVEs related to Deserialization of Untrusted Data and CSRF are particularly worrying, indicating potential for severe compromise. The taint analysis revealing two flows with unsanitized paths and two high-severity taint issues further reinforces this concern, suggesting that even with seemingly robust checks, there are still avenues for attackers to potentially inject malicious data. The bundled Select2 library, if outdated, could also introduce risks.

Overall, while the plugin appears to have implemented some good security controls, the historical vulnerability patterns and the identified high-severity taint flows indicate a need for careful monitoring and potential auditing. The low number of entry points and good practices in basic code sanitization are strengths, but these are overshadowed by the potential for serious exploitation indicated by past critical vulnerabilities and current taint analysis findings. Users should be aware of the historical risks and ensure this version is the most up-to-date patch available, especially considering the critical nature of past issues.

Key Concerns

  • Historical critical CVE (Deserialization/CSRF)
  • Historical medium CVE
  • Taint flows with unsanitized paths (2)
  • High severity taint flows (2)
  • Bundled library (Select2)
Vulnerabilities
2

Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Critical
1
Medium
1

2 total CVEs

CVE-2025-7697critical · 9.8Deserialization of Untrusted Data

Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 - Unauthenticated PHP Object Injection via verify_field_val Function

Jul 18, 2025 Patched in 1.1.2 (1d)
CVE-2025-30863medium · 4.3Cross-Site Request Forgery (CSRF)

Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.0.9 - Cross-Site Request Forgery

Mar 27, 2025 Patched in 1.1.0 (7d)
Code Analysis
Analyzed Mar 16, 2026

Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
8
28 prepared
Unescaped Output
72
396 escaped
Nonce Checks
18
Capability Checks
24
File Operations
1
External Requests
2
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

78% prepared36 total queries

Output Escaping

85% escaped468 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
settings_page (includes\plugin-pages.php:1522)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 39
actionvx_cf_add_meta_boxincludes\crmperks-cf.php:10
actioncfx_add_meta_boxincludes\plugin-pages.php:35
actioncfx_form_entry_updatedincludes\plugin-pages.php:36
actioncfx_form_post_note_addedincludes\plugin-pages.php:37
actioncfx_form_pre_note_deletedincludes\plugin-pages.php:38
actioncfx_form_pre_trash_leadsincludes\plugin-pages.php:39
actioncfx_form_pre_restore_leadsincludes\plugin-pages.php:40
filteradmin_menuincludes\plugin-pages.php:53
filtervx_cf_meta_boxes_rightincludes\plugin-pages.php:54
actionadmin_noticesincludes\plugin-pages.php:55
filterplugin_action_linksincludes\plugin-pages.php:56
actionvxcf_entry_submit_btnincludes\plugin-pages.php:57
actionvx_cf7_post_note_addedincludes\plugin-pages.php:59
actionvx_cf7_pre_note_deletedincludes\plugin-pages.php:60
actionvx_cf7_pre_trash_leadsincludes\plugin-pages.php:61
actionvx_cf7_pre_restore_leadsincludes\plugin-pages.php:62
actionvx_cf7_entry_updatedincludes\plugin-pages.php:63
actionvx_contact_post_note_addedincludes\plugin-pages.php:65
actionvx_contact_pre_note_deletedincludes\plugin-pages.php:66
actionvx_contact_pre_trash_leadsincludes\plugin-pages.php:67
actionvx_contact_pre_restore_leadsincludes\plugin-pages.php:68
actionvx_contact_entry_updatedincludes\plugin-pages.php:69
filtervx_callcenter_entries_actionincludes\plugin-pages.php:71
filtervx_callcenter_bulk_actionsincludes\plugin-pages.php:72
actionplugins_loadedintegration-for-contact-form-7-and-google-sheets.php:58
actioncfx_form_submittedintegration-for-contact-form-7-and-google-sheets.php:72
actionvxcf_entry_createdintegration-for-contact-form-7-and-google-sheets.php:73
actionvx_contact_createdintegration-for-contact-form-7-and-google-sheets.php:74
actionvx_callcenter_entry_createdintegration-for-contact-form-7-and-google-sheets.php:75
filterwpcf7_before_send_mailintegration-for-contact-form-7-and-google-sheets.php:77
actionfrm_after_create_entryintegration-for-contact-form-7-and-google-sheets.php:79
actionninja_forms_after_submissionintegration-for-contact-form-7-and-google-sheets.php:80
actionwpforms_process_entry_saveintegration-for-contact-form-7-and-google-sheets.php:81
actionelementor_pro/forms/new_recordintegration-for-contact-form-7-and-google-sheets.php:83
actioninitintegration-for-contact-form-7-and-google-sheets.php:88
filterplugin_row_metawp\crmperks-notices.php:16
filteradmin_footer_textwp\crmperks-notices.php:30
actionadmin_noticeswp\crmperks-notices.php:32
filterplugins_apiwp\crmperks-notices.php:34
Maintenance & Trust

Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 15, 2025
PHP min version5.3
Downloads14K

Community Trust

Rating100/100
Number of ratings2
Active installs1K
Developer Profile

Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Developer Profile

CRM Perks

32 plugins · 105K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
349 days
View full developer profile
Detection Fingerprints

How We Detect Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integration-for-contact-form-7-and-google-sheets/css/style.css/wp-content/plugins/integration-for-contact-form-7-and-google-sheets/js/script.js
Version Parameters
integration-for-contact-form-7-and-google-sheets/css/style.css?ver=integration-for-contact-form-7-and-google-sheets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
vxcf_googlesheets_settings
Data Attributes
data-crmperks-cf7-sheets-id
JS Globals
vxcf_googlesheetsvxcf_googlesheets_pro
FAQ

Frequently Asked Questions about Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms