
GSheetConnector for WC Security & Risk Analysis
wordpress.org/plugins/wc-gsheetconnectorGoogle Sheet Integration for WooCommerce Plugin, Addon plugin of WooCommerce - Helps to send the orders directly to Google Sheets in a real-time.
Is GSheetConnector for WC Safe to Use in 2026?
Generally Safe
Score 97/100GSheetConnector for WC has a strong security track record. Known vulnerabilities have been patched promptly.
The wc-gsheetconnector plugin v1.4.6 exhibits a mixed security posture. On the positive side, it shows strong practices in areas like SQL query sanitization, with 100% of queries using prepared statements. The plugin also incorporates a reasonable number of nonce and capability checks, and its taint analysis indicates no critical or high-severity vulnerabilities related to unsanitized data flows. However, significant concerns arise from the presence of one AJAX handler without any authentication checks, creating a direct entry point for potential unauthorized actions. The vulnerability history, despite having no currently unpatched CVEs, reveals a past pattern of medium-severity vulnerabilities, primarily related to CSRF and missing authorization. This suggests that while the developers may have addressed past issues, there's a recurring theme of authorization and access control weaknesses that warrants attention. The presence of bundled libraries like Guzzle and Freemius also introduces a dependency risk if they are not kept up-to-date.
Overall, the plugin has strengths in secure coding practices for data handling, but the unprotected AJAX endpoint and historical authorization issues are notable weaknesses. The risk is elevated by the potential for attackers to exploit the unprotected AJAX handler, and the historical vulnerability trends suggest that careful review of authorization logic is paramount. While the current version might be free of critical flaws according to the static analysis, the attack surface and past issues indicate a moderate level of risk that could be mitigated by addressing the unprotected entry point and reinforcing authorization checks across all handlers.
Key Concerns
- Unprotected AJAX handler found
- Vulnerability history shows past authorization issues
- Bundled libraries may be outdated (Freemius v1.0)
GSheetConnector for WC Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WooCommerce Google Sheet Connector <= 1.3.20 - Cross-Site Request Forgery
WooCommerce Google Sheet Connector <= 1.3.11 - Missing Authorization
WooCommerce Google Sheet Connector < 1.3.6 - Cross-Site Request Forgery
GSheetConnector for WC Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
GSheetConnector for WC Attack Surface
AJAX Handlers 10
WordPress Hooks 23
Maintenance & Trust
GSheetConnector for WC Maintenance & Trust
Maintenance Signals
Community Trust
GSheetConnector for WC Alternatives
StoreCustomizer – A plugin to Customize all WooCommerce Pages
woocustomizer
A store editor plugin for editing all WooCommerce store and product pages, cart, checkout and user account pages, all within the WordPress Customizer
All-in-One Addons for Elementor – WidgetKit
widgetkit-for-elementor
Build stunning websites with Elementor using premium widgets for WooCommerce, LearnDash & LearnPress. Free creative, content & dynamic widget pack.
Ibtana – Ecommerce Product Addons
ibtana-ecommerce-product-addons
Ibtana - Ecommerce Product Addons, you get to explore so many options for editing the product page by simple drag and drop functionality.
Widgets for WooCommerce Products on Elementor
woo-products-widgets-for-elementor
Woo Products widget is a plugin that allows adding WooCommerce Products and Categories into stylish grid and listing layouts to the pages built with E …
GST Invoice for WooCommerce
woo-gst
This plugin is for GST tax setting. It set all tax including Tax slabs setting for CGST, SGST and IGST automatically.
GSheetConnector for WC Developer Profile
11 plugins · 63K total installs
How We Detect GSheetConnector for WC
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-gsheetconnector/assets/css/styles.css/wp-content/plugins/wc-gsheetconnector/assets/css/wc-gsheetconnector-admin.css/wp-content/plugins/wc-gsheetconnector/assets/js/wc-gsheetconnector-admin.js/wp-content/plugins/wc-gsheetconnector/assets/js/wc-gsheetconnector-frontend.js/wp-content/plugins/wc-gsheetconnector/assets/js/wc-gsheetconnector-admin-script.js/wp-content/plugins/wc-gsheetconnector/assets/js/wc-gsheetconnector-admin.js/wp-content/plugins/wc-gsheetconnector/assets/js/wc-gsheetconnector-frontend.js/wp-content/plugins/wc-gsheetconnector/assets/js/wc-gsheetconnector-admin-script.jswc-gsheetconnector/assets/css/styles.css?ver=wc-gsheetconnector/assets/css/wc-gsheetconnector-admin.css?ver=wc-gsheetconnector/assets/js/wc-gsheetconnector-admin.js?ver=wc-gsheetconnector/assets/js/wc-gsheetconnector-frontend.js?ver=wc-gsheetconnector/assets/js/wc-gsheetconnector-admin-script.js?ver=HTML / DOM Fingerprints
wc-gsheetconnector-admin-wrapdata-plugin-slug="wc-gsheetconnector"data-plugin-version="1.4.6"wc_gsheetconnector_admin_paramswc_gsheetconnector_params/wp-json/wc-gsheetconnector/v1/settings/wp-json/wc-gsheetconnector/v1/admin-options