
SFTP Sync for Google Sheets Security & Risk Analysis
wordpress.org/plugins/sftp-sync-for-google-sheetsAutomatically receive Google Sheets exports and upload them to your SFTP server. Supports daily automated syncs.
Is SFTP Sync for Google Sheets Safe to Use in 2026?
Generally Safe
Score 100/100SFTP Sync for Google Sheets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sftp-sync-for-google-sheets v1.5.0 plugin exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to best practices, with a complete absence of unauthenticated entry points (AJAX handlers, REST API routes, shortcodes, cron events) and a significant number of nonce and capability checks relative to its entry points. The code also effectively utilizes prepared statements for all SQL queries and properly escapes all output, eliminating common web application vulnerabilities. The absence of dangerous functions and external HTTP requests further strengthens its security profile. The taint analysis, while limited in scope, shows no critical or high-severity issues with unsanitized paths, suggesting that any path manipulation risks are contained or handled appropriately.
Furthermore, the plugin's vulnerability history is remarkably clean, with no recorded CVEs, indicating a consistent track record of secure development or timely patching. The lack of common vulnerability types also points towards a mature and well-maintained codebase. While the static analysis revealed two flows with unsanitized paths, the absence of critical or high severity taint findings suggests these are likely low-risk or mitigated by other security controls not explicitly detailed in the taint analysis summary. The presence of file operations, while not inherently a vulnerability, is an area that always warrants careful review in production environments, though no specific risks were flagged here.
In conclusion, sftp-sync-for-google-sheets v1.5.0 appears to be a secure plugin. Its strengths lie in its robust input validation, strict authentication/authorization on entry points, secure SQL handling, and comprehensive output escaping. The lack of past vulnerabilities is a significant positive indicator. The only area for potential, albeit minor, concern is the two identified taint flows with unsanitized paths, but given the overall strong security signals and lack of reported critical issues, this is likely a low-risk observation. The plugin has a very small attack surface and appears to be well-defended.
Key Concerns
- Flows with unsanitized paths detected
SFTP Sync for Google Sheets Security Vulnerabilities
SFTP Sync for Google Sheets Release Timeline
SFTP Sync for Google Sheets Code Analysis
Output Escaping
Data Flow Analysis
SFTP Sync for Google Sheets Attack Surface
REST API Routes 2
WordPress Hooks 4
Maintenance & Trust
SFTP Sync for Google Sheets Maintenance & Trust
Maintenance Signals
Community Trust
SFTP Sync for Google Sheets Alternatives
GSheets Connector
sheetlink
Sync your WordPress posts, custom post types, and WooCommerce orders, including custom fields, to Google Spreadsheets using available filter hooks.
OttoKit: All-in-One Automation Platform
suretriggers
Experience the power of automation within WordPress: Connect 1,300+ apps, automate manual tasks, and unlock your full potential. Get started now!
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin
uncanny-automator
Uncanny Automator is the easiest and most powerful way to connect your WordPress plugins, sites and apps together with powerful automations.
Bit integrations – Easy Automator with no-code automation, integrate Webhook and automate 300+ Platform
bit-integrations
Perfect Automation and integration plugin: Connect 300+ platforms and automate CRM, Email marketing tools, Google Sheets, Contact forms, LMS and more
WP Fusion Lite – Marketing Automation and CRM Integration for WordPress
wp-fusion-lite
WP Fusion Lite synchronizes your WordPress users with contact records in your CRM or marketing automation system.
SFTP Sync for Google Sheets Developer Profile
3 plugins · 10 total installs
How We Detect SFTP Sync for Google Sheets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sftp-sync-for-google-sheets/assets/css/admin.css/wp-content/plugins/sftp-sync-for-google-sheets/assets/js/admin.js/wp-content/plugins/sftp-sync-for-google-sheets/assets/js/admin.jssftp-sync-for-google-sheets/assets/css/admin.css?ver=sftp-sync-for-google-sheets/assets/js/admin.js?ver=HTML / DOM Fingerprints
gsheet-sftp-wrapgsheet-sftp-api-keygsheet-sftp-endpointgsheet-sftp-sectiongsheet-sftp-logslog-successlog-errorlog-infogsheet_sftp_api_keygsheet_sftp_scheduledaily-hour-rowSFTP_SYNC_GS_VERSION/wp-json/sftp-sync-gs/v1/sync