Gsheet Contact Addons & ShortCode Security & Risk Analysis

wordpress.org/plugins/shortcode-addons-for-google-sheet-api

Send your Contact Form 7 data directly to your Google Sheets spreadsheet API.

0 active installs v1.0.2 PHP 5.6+ WP 1.0.2+ Updated Aug 4, 2021
cf7contact-form-7contact-form-7-integrationscontact-formsgoogle-sheets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gsheet Contact Addons & ShortCode Safe to Use in 2026?

Generally Safe

Score 85/100

Gsheet Contact Addons & ShortCode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin 'shortcode-addons-for-google-sheet-api' v1.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs, critical or high severity taint flows, and the consistent use of prepared statements for SQL queries are significant positive indicators. Furthermore, the plugin demonstrates good practices by implementing nonce and capability checks on its entry points and escaping a very high percentage of its output. The limited attack surface with all entry points appearing to have authentication checks further strengthens its security profile.

However, there are a few minor points of consideration. The presence of file operations, while not inherently dangerous, always carries a potential risk if not handled with extreme care. The bundling of the Guzzle library, while a useful dependency, could represent a risk if it's not kept up-to-date or if it contains its own vulnerabilities. The static analysis reports 2 AJAX handlers, and while the report states 0 are unprotected, it's crucial to ensure these checks are robust and correctly implemented to prevent any potential unauthorized actions.

Overall, the plugin appears to be well-developed from a security perspective, with a commendable track record and good implementation of security best practices. The focus should remain on maintaining this vigilance, especially regarding bundled libraries and the thoroughness of authentication checks on all entry points.

Key Concerns

  • Bundled library (Guzzle) may be outdated
  • File operations present
Vulnerabilities
None known

Gsheet Contact Addons & ShortCode Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Gsheet Contact Addons & ShortCode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
82 escaped
Nonce Checks
2
Capability Checks
3
File Operations
5
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

98% escaped84 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
get_key_token_api (inc\class\class-service.php:120)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Gsheet Contact Addons & ShortCode Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_get_key_token_apiinc\class\class-service.php:25
authwp_ajax_del_active_loginc\class\class-service.php:26
WordPress Hooks 8
actionadmin_menuifnt-Gsheet.php:48
actioninitifnt-Gsheet.php:49
actionadmin_initifnt-Gsheet.php:52
actionadmin_print_stylesifnt-Gsheet.php:180
actionadmin_print_scriptsifnt-Gsheet.php:181
filterwpcf7_editor_panelsinc\class\class-service.php:28
actionwpcf7_after_saveinc\class\class-service.php:30
actionwpcf7_mail_sentinc\class\class-service.php:31
Maintenance & Trust

Gsheet Contact Addons & ShortCode Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedAug 4, 2021
PHP min version5.6
Downloads994

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Gsheet Contact Addons & ShortCode Developer Profile

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gsheet Contact Addons & ShortCode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shortcode-addons-for-google-sheet-api/assets/css/gscript-free-style.css/wp-content/plugins/shortcode-addons-for-google-sheet-api/assets/js/gscript-free-script.js/wp-content/plugins/shortcode-addons-for-google-sheet-api/pages/google-sheet-settings.php
Script Paths
/wp-content/plugins/shortcode-addons-for-google-sheet-api/assets/js/gscript-free-script.js
Version Parameters
shortcode-addons-for-google-sheet-api/assets/css/gscript-free-style.css?ver=shortcode-addons-for-google-sheet-api/assets/js/gscript-free-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
iFntBoxAPIBox-Input-APIget-account
Data Attributes
gsheet-tokendel-active-logsave-access-codeGsheet-ajax-nonce
Shortcode Output
<h1Google Sheet API - ShortCode & Contact Form 7<h2 class="title">Google Sheets Get API</h2><label>Google Access Code</label>
FAQ

Frequently Asked Questions about Gsheet Contact Addons & ShortCode