
Sheet2Site Security & Risk Analysis
wordpress.org/plugins/sheet2siteSheet2Site - Embed your Google Sheet into your WordPress website.
Is Sheet2Site Safe to Use in 2026?
Use With Caution
Score 64/100Sheet2Site has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The Sheet2Site plugin version 1.0.18 presents a mixed security posture. While it demonstrates some good practices like using prepared statements for all SQL queries and performing external HTTP requests, its overall security is compromised by critical weaknesses. The static analysis reveals a concerning lack of authorization checks on a significant portion of its attack surface, specifically an AJAX handler. This, combined with a very low percentage of properly escaped output, creates a substantial risk of cross-site scripting (XSS) vulnerabilities and potentially other injection attacks. The vulnerability history further reinforces these concerns, highlighting a known medium severity XSS vulnerability that remains unpatched. This ongoing, unaddressed issue, coupled with the structural weaknesses identified in the code, indicates a plugin that requires immediate attention from its developers and administrators.
Key Concerns
- Unpatched CVE: 1 Medium
- AJAX handler without auth checks
- Low percentage of output escaping
- Lack of capability checks
Sheet2Site Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Sheet2Site <= 1.0.18 - Authenticated (Contributor+) Stored Cross-Site Scripting
Sheet2Site Code Analysis
Output Escaping
Sheet2Site Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Sheet2Site Maintenance & Trust
Maintenance Signals
Community Trust
Sheet2Site Alternatives
Sheet Monkey's Contact Form 7 to Google Sheets
cf7-to-google-sheets
The simple and secure way to connect Contact Form 7 to Google Sheets.
GSheets Connector
sheetlink
Sync your WordPress posts, custom post types, and WooCommerce orders, including custom fields, to Google Spreadsheets using available filter hooks.
LiveSheets: Google Sheets | Data table | Spreadsheets
livesheets
Transform google spreadsheets, google sheets into stunning data tables.
WPGSI: Spreadsheet Integration
wpgsi
Google sheet two-way sync 🔄 WordPress | WooCommerce | Contact form 7 | DB table | Google sheet as a Table.
GSheetConnector for Gravity Forms – Send Gravity Forms Entries to Google Sheets in Real-Time
gsheetconnector-gravity-forms
Send Gravity Forms entries to Google Sheets in real-time. Automatically sync Gravity Forms submissions to Google Sheets with secure Google Sheets inte …
Sheet2Site Developer Profile
1 plugin · 400 total installs
How We Detect Sheet2Site
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sheet2site/assets/sheet2site.js/wp-content/plugins/sheet2site/assets/sheet2site.csshttps://sheet2site.com/js/embedded.jssheet2site/style.css?ver=sheet2site/script.js?ver=HTML / DOM Fingerprints
sheet2site-activationsheet2site-helpdata-sheet2sitesheet2siteAdmin[sheet2site key=