
FormsDB – Save Elementor Forms to Google Sheets & Post Type Security & Risk Analysis
wordpress.org/plugins/sb-elementor-contact-form-dbConnect Elementor forms with Google Sheets to sync form entries, or save form submissions in any post type using Elementor Pro or Hello Plus forms.
Is FormsDB – Save Elementor Forms to Google Sheets & Post Type Safe to Use in 2026?
Generally Safe
Score 98/100FormsDB – Save Elementor Forms to Google Sheets & Post Type has a strong security track record. Known vulnerabilities have been patched promptly.
The sb-elementor-contact-form-db plugin v2.1.7 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output. The absence of dangerous functions and file operations further contributes to its security. However, the presence of one AJAX handler without authentication checks presents a significant concern, potentially allowing unauthorized users to interact with plugin functionalities.
The vulnerability history reveals a concerning pattern, with three known CVEs, including one high-severity vulnerability. The types of past vulnerabilities, such as Cross-Site Scripting and Exposure of Sensitive Information, suggest potential weaknesses in input validation and output encoding that, despite current improvements, might indicate underlying architectural issues. The fact that none of the past vulnerabilities are currently unpatched is a positive sign, implying the developers have addressed previous issues.
Overall, while the plugin has made strides in security, the unauthenticated AJAX endpoint and the historical prevalence of critical vulnerability types warrant careful consideration. The attack surface is relatively small, but the unprotected entry point is a weakness that could be exploited. Continued vigilance and thorough testing of new versions are recommended.
Key Concerns
- AJAX handler without authentication check
- History of high severity vulnerability
- History of medium severity vulnerabilities
- Total known CVEs (3)
- Flows with unsanitized paths
FormsDB – Save Elementor Forms to Google Sheets & Post Type Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Contact Form DB - Elementor <= 1.7 - Reflected Cross-Site Scripting
Elementor Contact Form DB <= 1.5 - Sensitive Information Disclosure
Elementor Contact Form DB <= 1.5 - Cross-Site Request Forgery
FormsDB – Save Elementor Forms to Google Sheets & Post Type Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
FormsDB – Save Elementor Forms to Google Sheets & Post Type Attack Surface
AJAX Handlers 9
WordPress Hooks 64
Scheduled Events 8
Maintenance & Trust
FormsDB – Save Elementor Forms to Google Sheets & Post Type Maintenance & Trust
Maintenance Signals
Community Trust
FormsDB – Save Elementor Forms to Google Sheets & Post Type Alternatives
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
GSheetConnector for Elementor Forms – Sync Elementor Forms to Google Sheets
gsheetconnector-for-elementor-forms
Sync Elementor Forms and MetForm to Google Sheets in real-time with secure Google Sheets integration and automatic form submission sync.
WPSyncSheets For WPForms – Google Sheets Connector for WPForms & Real‑Time Data Export
wpsyncsheets-wpforms
Connect WPForms to Google Sheets and automatically sync form entries in real-time. Eliminate manual data entry and simplify your workflow.
Contact Form 7 Database Manager Addon – CF7DBM
form-data-manager
Save contact form 7 submissions to the WP database with this CF7 addon. Never lose important messages, leads, and requests again.
Contact Form Extender for Divi – Submissions DB & Extra Fields
contact-form-extender-for-divi-builder
Extend Divi Contact Form module with file upload field, country code dropdown and save Divi form submissions in the database.
FormsDB – Save Elementor Forms to Google Sheets & Post Type Developer Profile
19 plugins · 109K total installs
How We Detect FormsDB – Save Elementor Forms to Google Sheets & Post Type
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sb-elementor-contact-form-db/assets/css/admin-style.css/wp-content/plugins/sb-elementor-contact-form-db/assets/css/common-style.css/wp-content/plugins/sb-elementor-contact-form-db/assets/js/admin-scripts.js/wp-content/plugins/sb-elementor-contact-form-db/assets/js/cpfm-common-scripts.js/wp-content/plugins/sb-elementor-contact-form-db/assets/js/jquery.validate.min.js/wp-content/plugins/sb-elementor-contact-form-db/assets/js/sweetalert.min.js/wp-content/plugins/sb-elementor-contact-form-db/assets/js/validation.js/wp-content/plugins/sb-elementor-contact-form-db/assets/js/admin-scripts.js/wp-content/plugins/sb-elementor-contact-form-db/assets/js/cpfm-common-scripts.js/wp-content/plugins/sb-elementor-contact-form-db/assets/js/jquery.validate.min.js/wp-content/plugins/sb-elementor-contact-form-db/assets/js/sweetalert.min.js/wp-content/plugins/sb-elementor-contact-form-db/assets/js/validation.jssb-elementor-contact-form-db/assets/css/admin-style.css?ver=sb-elementor-contact-form-db/assets/css/common-style.css?ver=sb-elementor-contact-form-db/assets/js/admin-scripts.js?ver=sb-elementor-contact-form-db/assets/js/cpfm-common-scripts.js?ver=sb-elementor-contact-form-db/assets/js/jquery.validate.min.js?ver=sb-elementor-contact-form-db/assets/js/sweetalert.min.js?ver=sb-elementor-contact-form-db/assets/js/validation.js?ver=HTML / DOM Fingerprints
cpfm-feedback-form-wrappercpfm-feedback-formcpfm-form-fieldcpfm-textareacpfm-submit-button<!-- Main FDBGP_Main Instance. --><!-- Ensures only one instance of FDBGP_Main is loaded or can be loaded. --><!-- FDBGP_Main Constructor. --><!-- Backward Compatibility: Save old class name for set an alias after the new class is loaded -->+3 moredata-fdbgp-iddata-fdbgp-settingsFDBGP_PLUGIN_VERSIONfdbgp_google_settingsformdb_initial_versionformdb_initial_version_migration