Pushrow — WordPress to Google Sheets Sync (WooCommerce, CF7, Forms & More) Security & Risk Analysis

wordpress.org/plugins/pushrow-for-google-sheets

Push WordPress data to Google Sheets in real time. Sync posts, pages, users & Contact Form 7 entries — no coding required.

0 active installs v0.0.2 PHP 7.4+ WP 5.0+ Updated Apr 1, 2026
contact-form-7exportgoogle-sheetsspreadsheetsync
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pushrow — WordPress to Google Sheets Sync (WooCommerce, CF7, Forms & More) Safe to Use in 2026?

Generally Safe

Score 100/100

Pushrow — WordPress to Google Sheets Sync (WooCommerce, CF7, Forms & More) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "pushrow-for-google-sheets" plugin version 0.0.2 demonstrates a generally good security posture based on the provided static analysis and vulnerability history. The code exhibits strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and all output properly escaped. The absence of dangerous functions, file operations, and critical or high-severity taint flows is also commendable. Furthermore, the plugin correctly implements nonce checks for all identified AJAX handlers and capability checks for its functionalities, indicating a thoughtful approach to access control. The vulnerability history is completely clean, with no recorded CVEs, which is a significant strength.

However, there are a couple of minor areas for improvement. The presence of two external HTTP requests, while not explicitly flagged as problematic in this analysis, could represent a potential attack vector if not handled with extreme care and input validation on the returned data. While the plugin boasts a total of 4 AJAX handlers, all of which appear to have authentication checks based on the provided data (0 without auth checks), a robust security analysis would ideally scrutinize the *effectiveness* of these checks and any potential logic flaws within the handlers themselves, although this level of detail is beyond static analysis alone. The bundled Guzzle library also presents a potential, albeit low, risk if it's an older version and has known vulnerabilities. Overall, the plugin is secure in its current state, but vigilance regarding external dependencies and the thoroughness of internal access controls is always advised.

Key Concerns

  • External HTTP requests
  • Bundled Guzzle library
Vulnerabilities
None known

Pushrow — WordPress to Google Sheets Sync (WooCommerce, CF7, Forms & More) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Pushrow — WordPress to Google Sheets Sync (WooCommerce, CF7, Forms & More) Release Timeline

v0.0.2Current
v0.0.1
Code Analysis
Analyzed Apr 16, 2026

Pushrow — WordPress to Google Sheets Sync (WooCommerce, CF7, Forms & More) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
34 prepared
Unescaped Output
0
144 escaped
Nonce Checks
4
Capability Checks
5
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared34 total queries

Output Escaping

100% escaped144 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<class-form-integration-ajax> (includes/integrations/class-form-integration-ajax.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Pushrow — WordPress to Google Sheets Sync (WooCommerce, CF7, Forms & More) Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_pushrow_form_get_sheetsincludes/integrations/class-form-integration-ajax.php:35
authwp_ajax_pushrow_form_get_tabsincludes/integrations/class-form-integration-ajax.php:36
authwp_ajax_pushrow_form_create_spreadsheetincludes/integrations/class-form-integration-ajax.php:37
authwp_ajax_pushrow_form_create_tabincludes/integrations/class-form-integration-ajax.php:38
WordPress Hooks 12
actionadmin_menuincludes/admin/class-admin-menu.php:18
actionadmin_enqueue_scriptsincludes/admin/class-admin-menu.php:19
actionadmin_headincludes/admin/class-admin-menu.php:20
actionrest_api_initincludes/admin/class-rest-api.php:39
filterwpcf7_editor_panelsincludes/integrations/class-cf7-sheets.php:30
actionwpcf7_after_saveincludes/integrations/class-cf7-sheets.php:33
actionadmin_enqueue_scriptsincludes/integrations/class-cf7-sheets.php:36
actionwpcf7_submitincludes/integrations/class-cf7-sheets.php:42
filterwpcf7_skip_mailincludes/integrations/class-cf7-sheets.php:47
actionadmin_noticespushrow-for-google-sheets.php:77
actionplugins_loadedpushrow-for-google-sheets.php:104
actionplugins_loadedpushrow-for-google-sheets.php:109
Maintenance & Trust

Pushrow — WordPress to Google Sheets Sync (WooCommerce, CF7, Forms & More) Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedApr 1, 2026
PHP min version7.4
Downloads167

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Pushrow — WordPress to Google Sheets Sync (WooCommerce, CF7, Forms & More) Developer Profile

Ankit Panchal

8 plugins · 21K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
701 days
View full developer profile
Detection Fingerprints

How We Detect Pushrow — WordPress to Google Sheets Sync (WooCommerce, CF7, Forms & More)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pushrow-for-google-sheets/assets/js/admin-app.js/wp-content/plugins/pushrow-for-google-sheets/assets/css/admin.css
Script Paths
/wp-content/plugins/pushrow-for-google-sheets/assets/js/admin-app.js
Version Parameters
pushrow-for-google-sheets/assets/js/admin-app.js?ver=pushrow-for-google-sheets/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
pushrow-admin-appspinner is-active
Data Attributes
id="pushrow-admin-app"
FAQ

Frequently Asked Questions about Pushrow — WordPress to Google Sheets Sync (WooCommerce, CF7, Forms & More)