
GSheets Connector Security & Risk Analysis
wordpress.org/plugins/sheetlinkSync your WordPress posts, custom post types, and WooCommerce orders, including custom fields, to Google Spreadsheets using available filter hooks.
Is GSheets Connector Safe to Use in 2026?
Mostly Safe
Score 70/100GSheets Connector is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "sheetlink" plugin v1.1.1 presents a mixed security posture. On the positive side, it demonstrates good practices in SQL query handling, utilizing prepared statements exclusively and also shows a high percentage of properly escaped output. Nonce checks are also present on all identified AJAX entry points, which is a commendable security measure.
However, significant concerns arise from the attack surface analysis. The plugin has a single AJAX handler, and crucially, this handler lacks authentication checks. This is a direct entry point for unauthenticated users to interact with the plugin's backend functionality, posing a considerable risk. While the taint analysis did not reveal critical or high-severity issues, the presence of "flows with unsanitized paths" suggests potential for vulnerabilities if the sanitized data is later used in a sensitive operation.
The vulnerability history reveals a pattern of "Deserialization of Untrusted Data" with one unpatched medium-severity CVE. This, combined with the unauthenticated AJAX handler, indicates a concerning tendency for the plugin to expose itself to risks that require careful validation of incoming data. The plugin's strengths in SQL and output handling are overshadowed by the critical vulnerability of an unauthenticated AJAX endpoint and a history of deserialization issues.
Key Concerns
- Unprotected AJAX handler
- Unpatched medium severity CVE
- Flows with unsanitized paths
GSheets Connector Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
GSheets Connector <= 1.1.1 - Authenticated (Administrator+) PHP Object Injection
GSheets Connector Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
GSheets Connector Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
GSheets Connector Maintenance & Trust
Maintenance Signals
Community Trust
GSheets Connector Alternatives
OttoKit: All-in-One Automation Platform
suretriggers
Experience the power of automation within WordPress: Connect 1,300+ apps, automate manual tasks, and unlock your full potential. Get started now!
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin
uncanny-automator
Uncanny Automator is the easiest and most powerful way to connect your WordPress plugins, sites and apps together with powerful automations.
Bit integrations – Easy Automator with no-code automation, integrate Webhook and automate 300+ Platform
bit-integrations
Perfect Automation and integration plugin: Connect 300+ platforms and automate CRM, Email marketing tools, Google Sheets, Contact forms, LMS and more
FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)
fusewp
Subscribe WordPress users to CRM & email marketing software. Constant Contact, Mailchimp ActiveCampaign MailerLite Brevo Klaviyo AWeber HubSpot etc
WPGSI: Spreadsheet Integration
wpgsi
Google sheet two-way sync 🔄 WordPress | WooCommerce | Contact form 7 | DB table | Google sheet as a Table.
GSheets Connector Developer Profile
3 plugins · 110 total installs
How We Detect GSheets Connector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sheetlink/assets/css/select2.min.css/wp-content/plugins/sheetlink/assets/css/style.css/wp-content/plugins/sheetlink/assets/js/raogsi.js/wp-content/plugins/sheetlink/assets/js/select2.min.js/wp-content/plugins/sheetlink/assets/js/raogsi.js/wp-content/plugins/sheetlink/assets/js/select2.min.jssheetlink/assets/css/select2.min.css?ver=sheetlink/assets/css/style.css?ver=sheetlink/assets/js/raogsi.js?ver=sheetlink/assets/js/select2.min.js?ver=HTML / DOM Fingerprints
raogsi-dashboard-wrapper<!-- Rao GSI Dashboard --><!-- Rao GSI New Integration --><!-- RAOGSI Edit Integration --><!-- Render single integration object -->+8 moredata-wp-sourcedata-integration-idraogsi_params