
Sheetable – Google Sheets to WP Table Security & Risk Analysis
wordpress.org/plugins/sheetable-datatable-from-google-sheetTurn Google Sheets into WP tables with search, sorting & pagination. No API key needed. Ultra-lightweight.
Is Sheetable – Google Sheets to WP Table Safe to Use in 2026?
Generally Safe
Score 100/100Sheetable – Google Sheets to WP Table has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "sheetable-datatable-from-google-sheet" version 1.0.2 exhibits a generally good security posture, with several positive indicators. The code demonstrates a strong adherence to secure coding practices by using prepared statements for nearly all SQL queries and ensuring 100% proper output escaping. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. The vulnerability history is also clean, with no recorded CVEs, suggesting a well-maintained and secure codebase over time.
However, there are notable concerns that detract from an otherwise positive assessment. The presence of one REST API route without permission callbacks represents a significant attack vector. Furthermore, the static analysis found one flow with unsanitized paths, which, although not classified as critical or high severity in the taint analysis, still warrants attention as it indicates potential for insecure data handling. The complete lack of nonce checks across all entry points is another significant weakness, especially given the presence of unprotected REST API routes.
In conclusion, while the plugin demonstrates strengths in data handling and SQL security, the unprotected REST API route and the absence of nonce checks are substantial security weaknesses. The clean vulnerability history is a positive sign, but it does not negate the immediate risks identified in the static and taint analysis. Addressing the unprotected entry point and implementing nonce checks on all handlers would significantly improve the plugin's security.
Key Concerns
- REST API route without permission callbacks
- Flow with unsanitized paths
- No nonce checks
Sheetable – Google Sheets to WP Table Security Vulnerabilities
Sheetable – Google Sheets to WP Table Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Sheetable – Google Sheets to WP Table Attack Surface
REST API Routes 7
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
Sheetable – Google Sheets to WP Table Maintenance & Trust
Maintenance Signals
Community Trust
Sheetable – Google Sheets to WP Table Alternatives
FlexTable – Data Table Sync with Google Sheets
sheets-to-wp-table-live-sync
Turn Google Sheets into live WordPress tables. Embed, sync, and customize data instantly with search, filters, and styling - no coding needed.
Stylish Google Sheet Reader – Embed Google Sheets as Interactive Tables with Built-in Form Submissions
stylish-google-sheet-reader
Effortlessly create responsive, searchable, auto-refreshable data tables — now with built-in form submissions to receive orders or inquiries directly.
Table Builder
table-builder
Wordpress Table plugin enables you to create beautiful list of your posts with search and column sorting. Drag and drop Column selection and Table bui …
Ninja Tables – Easy Data Table Builder
ninja-tables
Best WordPress table builder plugin packed with versatile features to create fully responsive data tables of any kind.
Data Tables Generator by Supsystic
data-tables-generator-by-supsystic
Create data tables with charts and graphs. Custom design, navigation, searching and ordering functions. Export to PDF, CSV, Print. Excel spreadsheet.
Sheetable – Google Sheets to WP Table Developer Profile
1 plugin · 50 total installs
How We Detect Sheetable – Google Sheets to WP Table
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sheetable-datatable-from-google-sheet/assets/css/admin.css/wp-content/plugins/sheetable-datatable-from-google-sheet/assets/js/admin.jssheetable-datatable-from-google-sheet/assets/css/admin.css?ver=sheetable-datatable-from-google-sheet/assets/js/admin.js?ver=HTML / DOM Fingerprints
sheetable_performance_sheetableAdmin/sheetable/v1/