
Sheet to Table Live Sync for Google Sheet Security & Risk Analysis
wordpress.org/plugins/sheet-to-wp-table-for-google-sheetSync Google Sheets live on WordPress. Lightning-fast, cached tables using shortcodes or the intuitive Dashboard interface.
Is Sheet to Table Live Sync for Google Sheet Safe to Use in 2026?
Generally Safe
Score 99/100Sheet to Table Live Sync for Google Sheet has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'sheet-to-wp-table-for-google-sheet' version 1.0.3 exhibits a generally good security posture based on the static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events without proper authorization checks significantly limits the attack surface. The code also demonstrates strong practices regarding SQL queries, exclusively using prepared statements, and a high percentage of properly escaped output, indicating a focus on preventing common web vulnerabilities.
However, a few areas warrant attention. The presence of an external HTTP request, though singular, could potentially be a vector for information leakage or man-in-the-middle attacks if not handled securely. While the taint analysis revealed no critical or high severity unsanitized flows, and the overall output escaping is good, the 18% of unescaped output still presents a minor risk for cross-site scripting (XSS) vulnerabilities, particularly if user-supplied data is involved in these outputs. The plugin's history shows a single medium-severity CVE for XSS, which, although currently patched, highlights a past weakness in output sanitization that should remain a concern.
In conclusion, the plugin is robust in many security aspects, particularly its limited attack surface and secure database interactions. The primary weaknesses lie in the potential for vulnerabilities within the external HTTP request and the remaining unescaped output, especially given the past XSS vulnerability. Continuous monitoring for future vulnerabilities and ensuring all external requests are made securely will be crucial for maintaining its security.
Key Concerns
- Unescaped output present
- External HTTP request present
- Past medium CVE for XSS
Sheet to Table Live Sync for Google Sheet Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Sheet to Table Live Sync for Google Sheet <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via STWT_Sheet_Table Shortcode
Sheet to Table Live Sync for Google Sheet Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Sheet to Table Live Sync for Google Sheet Attack Surface
WordPress Hooks 14
Maintenance & Trust
Sheet to Table Live Sync for Google Sheet Maintenance & Trust
Maintenance Signals
Community Trust
Sheet to Table Live Sync for Google Sheet Alternatives
Bulky – Bulk Edit Products for WooCommerce
bulky-bulk-edit-products-for-woo
A helpful tool that allows you to bulk edit available attributes of products such as ID, Title, Content,...
PBULKiT – Bulk Edit WooCommerce Products
ithemeland-woo-bulk-product-editor-lite
Stop wasting hours editing products one by one. Bulk edit thousands of WooCommerce products, variations, and prices in minutes.
Bulk Edit Products – Price, Stock, SKU & Inventory Manager for WooCommerce
bulk-edit-product-for-woocommerce
Bulk edit WooCommerce product prices, stock, SKU, dimensions, tax, and more — update hundreds of products in seconds from one screen.
Booster for WooCommerce Management with Analytics Dashboard – Shop Explorer
shop-explorer
The ultimate Booster for WooCommerce Management, bulk editor & analytics dashboard. Bulk edit thousands of products, orders in minutes with lightn …
SimpleBeat – Filter & Edit
simplebeat-filter-edit
Lightweight, simple, yet effective and powerful plugin for bulk editing product prices and taxonomies.
Sheet to Table Live Sync for Google Sheet Developer Profile
12 plugins · 20K total installs
How We Detect Sheet to Table Live Sync for Google Sheet
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sheet-to-wp-table-for-google-sheet/assets/css/stwt-common.css/wp-content/plugins/sheet-to-wp-table-for-google-sheet/assets/css/stwt-admin-page.css/wp-content/plugins/sheet-to-wp-table-for-google-sheet/assets/js/stwt-admin-page.js/wp-content/plugins/sheet-to-wp-table-for-google-sheet/assets/js/stwt-script.js/wp-content/plugins/sheet-to-wp-table-for-google-sheet/assets/js/stwt-admin-page.js/wp-content/plugins/sheet-to-wp-table-for-google-sheet/assets/js/stwt-script.jssheet-to-wp-table-for-google-sheet/assets/css/stwt-common.css?ver=sheet-to-wp-table-for-google-sheet/assets/css/stwt-admin-page.css?ver=sheet-to-wp-table-for-google-sheet/assets/js/stwt-admin-page.js?ver=sheet-to-wp-table-for-google-sheet/assets/js/stwt-script.js?ver=HTML / DOM Fingerprints
stwt-admin-menustwt-page-title<!--This is admin page -->data-plugin-nameSTWT_ADMIN_PAGE[stwt_google_sheet_table