[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhhywswvWa0saCcfLQnNGad4skEVHLZHHByLICeM33WY":3,"$figvPEPsFdRNRECY7u3fbi4mjvyIXPuE2zrz89U7hf5I":295,"$f_Y8aT6LKT6ijydp5S-qgKZpD8o9CV7B7eCeG4-uEMG4":299},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":36,"analysis":71,"fingerprints":271},"workbook-connector-for-microsoft-365","Workbook Connector for Microsoft 365","1.0.5","Abdullah Kaludi","https:\u002F\u002Fprofiles.wordpress.org\u002Fabdullah17\u002F","\u003Cp>\u003Cstrong>Workbook Connector for Microsoft 365\u003C\u002Fstrong> allows you to connect your WordPress website with Microsoft Excel files stored in Microsoft 365 \u002F OneDrive.\u003C\u002Fp>\n\u003Cp>The plugin enables automatic transfer of form submissions into Excel tables — no manual exports, CSV imports, or complicated automation workflows.\u003C\u002Fp>\n\u003Cp>Built for performance, reliability, and scalability, this plugin uses the official \u003Cstrong>Microsoft Graph API\u003C\u002Fstrong> for secure communication with Microsoft services.\u003C\u002Fp>\n\u003Cp>✔ Automatically send form entries to Excel\u003Cbr \u002F>\n✔ Supports Fluent Forms\u003Cbr \u002F>\n✔ Supports Contact Form 7\u003Cbr \u002F>\n✔ Supports Gravity Forms\u003Cbr \u002F>\n✔ Supports WPForms\u003Cbr \u002F>\n✔ Works with Excel files stored in OneDrive\u003Cbr \u002F>\n✔ Select workbook, worksheet, and table\u003Cbr \u002F>\n✔ Secure OAuth connection with Microsoft\u003Cbr \u002F>\n✔ No coding required\u003Cbr \u002F>\n✔ Real-time form to Excel sync\u003C\u002Fp>\n\u003Cp>Perfect for:\u003C\u002Fp>\n\u003Cp>• Form automation\u003Cbr \u002F>\n• Customer inquiries\u003Cbr \u002F>\n• Lead generation\u003Cbr \u002F>\n• CRM integration\u003Cbr \u002F>\n• Data logging\u003Cbr \u002F>\n• Internal reporting\u003Cbr \u002F>\n• Reporting & analytics\u003Cbr \u002F>\n• Automation pipelines\u003C\u002Fp>\n\u003Ch3>Key Features\u003C\u002Fh3>\n\u003Cp>✅ \u003Cstrong>Microsoft 365 Integration\u003C\u002Fstrong>\u003Cbr \u002F>\nSecurely connect your WordPress website with Microsoft using OAuth authentication.\u003C\u002Fp>\n\u003Cp>✅ \u003Cstrong>Direct Excel Table Support\u003C\u002Fstrong>\u003Cbr \u002F>\nData is inserted directly into Excel tables for structured and reliable storage.\u003C\u002Fp>\n\u003Cp>✅ \u003Cstrong>Multi-Form Plugin Integration\u003C\u002Fstrong>\u003Cbr \u002F>\nSupports Fluent Forms, Contact Form 7, Gravity Forms, and WPForms.\u003C\u002Fp>\n\u003Cp>✅ \u003Cstrong>Dynamic Workbook Selection\u003C\u002Fstrong>\u003Cbr \u002F>\nChoose Excel workbooks directly from your OneDrive account.\u003C\u002Fp>\n\u003Cp>✅ \u003Cstrong>Worksheet & Table Detection\u003C\u002Fstrong>\u003Cbr \u002F>\nSelect exact worksheet and table for form data insertion.\u003C\u002Fp>\n\u003Cp>✅ \u003Cstrong>Real-Time Sync\u003C\u002Fstrong>\u003Cbr \u002F>\nForm entries are pushed instantly after submission.\u003C\u002Fp>\n\u003Cp>✅ \u003Cstrong>Performance Optimized\u003C\u002Fstrong>\u003Cbr \u002F>\nUses caching and Microsoft Graph API optimization for better performance.\u003C\u002Fp>\n\u003Cp>✅ \u003Cstrong>Secure & WordPress-Compliant\u003C\u002Fstrong>\u003Cbr \u002F>\nNonce verification, sanitization, and capability checks implemented.\u003C\u002Fp>\n\u003Ch3>Future Development\u003C\u002Fh3>\n\u003Cp>Workbook Connector for Microsoft 365 is built on a modular architecture, allowing rapid expansion without affecting current integrations.\u003C\u002Fp>\n\u003Cp>Upcoming integrations planned:\u003C\u002Fp>\n\u003Cp>• Ninja Forms\u003Cbr \u002F>\n• Formidable Forms\u003Cbr \u002F>\n• Forminator\u003Cbr \u002F>\n• JetFormBuilder\u003Cbr \u002F>\n• Elementor Forms\u003Cbr \u002F>\n• WooCommerce Orders\u003Cbr \u002F>\n• Easy Digital Downloads\u003Cbr \u002F>\n• Divi Forms\u003Cbr \u002F>\n• Avada Forms\u003C\u002Fp>\n\u003Cp>Development priorities are guided by user feedback.\u003C\u002Fp>\n\u003Ch3>Requirements\u003C\u002Fh3>\n\u003Cp>• WordPress 5.8 or higher\u003Cbr \u002F>\n• PHP 7.4 or higher\u003Cbr \u002F>\n• Microsoft 365 account\u003Cbr \u002F>\n• OneDrive storage enabled\u003Cbr \u002F>\n• At least one supported form plugin installed:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Fluent Forms\u003C\u002Fli>\n\u003Cli>Contact Form 7\u003C\u002Fli>\n\u003Cli>Gravity Forms\u003C\u002Fli>\n\u003Cli>WPForms\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>How It Works\u003C\u002Fh3>\n\u003Col>\n\u003Cli>User submits a supported WordPress form\u003C\u002Fli>\n\u003Cli>Workbook Connector captures the submission\u003C\u002Fli>\n\u003Cli>Microsoft Graph API sends the request\u003C\u002Fli>\n\u003Cli>Data is inserted into the selected Excel table\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Everything works automatically in real-time.\u003C\u002Fp>\n\u003Ch3>Security & Privacy\u003C\u002Fh3>\n\u003Cp>This plugin communicates directly with Microsoft Graph API using secure OAuth authentication.\u003C\u002Fp>\n\u003Cp>• No form submission data is stored on third-party servers\u003Cbr \u002F>\n• Data is transmitted only to Microsoft services\u003Cbr \u002F>\n• No analytics or tracking scripts\u003Cbr \u002F>\n• No third-party sharing\u003C\u002Fp>\n\u003Cp>All tokens are securely stored using the WordPress Options API.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin communicates with:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Microsoft Graph API\u003Cbr \u002F>\nService Provider: Microsoft Corporation\u003Cbr \u002F>\nService URL: https:\u002F\u002Fgraph.microsoft.com\u002F\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Purpose:\u003C\u002Fp>\n\u003Cp>• Retrieve Excel files\u003Cbr \u002F>\n• Retrieve worksheets\u003Cbr \u002F>\n• Retrieve tables\u003Cbr \u002F>\n• Insert rows\u003Cbr \u002F>\n• Fetch user account data\u003C\u002Fp>\n\u003Cp>Data Sent:\u003C\u002Fp>\n\u003Cp>• OAuth tokens\u003Cbr \u002F>\n• Workbook identifiers\u003Cbr \u002F>\n• Worksheet identifiers\u003Cbr \u002F>\n• Table identifiers\u003C\u002Fp>\n\u003Cp>Privacy Policy:\u003Cbr \u002F>\nhttps:\u002F\u002Fprivacy.microsoft.com\u002F\u003C\u002Fp>\n\u003Col>\n\u003Cli>OAuth Credential Service\u003Cbr \u002F>\nService Provider: GSheetConnector \u002F Western Deal\u003Cbr \u002F>\nService URL: https:\u002F\u002Foauth.gsheetconnector.com\u002F\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Purpose:\u003C\u002Fp>\n\u003Cp>• Retrieve Microsoft API credentials\u003Cbr \u002F>\n• Facilitate secure OAuth setup\u003C\u002Fp>\n\u003Cp>Data Sent:\u003C\u002Fp>\n\u003Cp>• Plugin identifier\u003Cbr \u002F>\n• Site request metadata\u003C\u002Fp>\n\u003Cp>No personal form submission data is transmitted.\u003C\u002Fp>\n\u003Ch3>Disclaimer\u003C\u002Fh3>\n\u003Cp>Microsoft, Excel, OneDrive, and Microsoft 365 are trademarks of Microsoft Corporation.\u003C\u002Fp>\n\u003Cp>This plugin is not affiliated with or endorsed by Microsoft.\u003C\u002Fp>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under GPLv2 or later.\u003C\u002Fp>\n","Connect WordPress forms to Microsoft Excel in Microsoft 365 and automatically send form submissions to Excel tables.",0,711,"2026-06-27T14:52:00.000Z","7.0.2","5.0","7.4",[18,19,20,21,22],"forms-to-excel","microsoft-365","microsoft-excel","onedrive-excel-sync","wordpress-form-integration","https:\u002F\u002Fwww.westerndeal.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fworkbook-connector-for-microsoft-365.1.0.5.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"abdullah17",1,30,94,"2026-08-29T02:10:51.791Z",[37,57],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":11,"num_ratings":11,"last_updated":47,"tested_up_to":14,"requires_at_least":48,"requires_php":49,"tags":50,"homepage":55,"download_link":56,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"vr-smtp-mailer","VR SMTP Mailer","2.0","Vinod Ram","https:\u002F\u002Fprofiles.wordpress.org\u002Fvinodkram\u002F","\u003Cp>VR SMTP Mailer replaces the default WordPress mail transport with SMTP or an OAuth-based mail API, with full support for Microsoft 365 (Office365), Outlook SMTP, and Microsoft Graph API.\u003C\u002Fp>\n\u003Cp>It is designed as a complete email solution for WordPress — combining SMTP delivery, OAuth authentication, and API-based sending in a single plugin, without requiring multiple paid extensions.\u003C\u002Fp>\n\u003Ch3>Why choose this plugin\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Works with Microsoft 365 \u002F Office365 and Outlook SMTP\u003C\u002Fli>\n\u003Cli>Supports both SMTP and OAuth (Graph API) in one plugin\u003C\u002Fli>\n\u003Cli>No need to install multiple plugins for authentication and email delivery\u003C\u002Fli>\n\u003Cli>Designed to work as a full wp_mail replacement\u003C\u002Fli>\n\u003Cli>Includes features commonly available only in paid plugins\u003C\u002Fli>\n\u003Cli>No subscriptions or locked features\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Send emails using either SMTP or an OAuth-based mail API (Graph-compatible).\u003Cbr \u002F>\nWorks with wp_mail() (for immediate sends):\u003Cbr \u002F>\nWhen WordPress sends emails through this plugin, it keeps the same structure as the default wp_mail() function. This includes support for multiple recipients, subject, message body, headers (From, Cc, Bcc, Reply-To, Content-Type), attachments, and inline images where supported.\u003Cbr \u002F>\nStandard WordPress filters like wp_mail, wp_mail_from, wp_mail_content_type, and phpmailer_init are applied in SMTP mode, so behavior remains consistent with native WordPress email handling.\u003Cbr \u002F>\nGraph API limitations:\u003Cbr \u002F>\nWhen using the Graph API, emails support HTML or plain text content, along with To, Cc, Bcc, and Reply-To fields. Attachments and inline images are supported, but typically limited to around 3 MB per file.\u003Cbr \u002F>\nCustom MIME headers are not fully supported, and only standard fields are mapped to the API. More complex email structures may behave differently compared to traditional PHP mail handling.\u003Cbr \u002F>\nEmail queue (WP-Cron):\u003Cbr \u002F>\nEmails can be queued and processed later using WP-Cron. Queued emails store only basic details such as recipient, subject, and message body. Attachments, headers, and inline images are not included in queued jobs.\u003Cbr \u002F>\nAutomatic OAuth token refresh:\u003Cbr \u002F>\nAccess tokens are refreshed automatically to ensure uninterrupted email delivery.\u003Cbr \u002F>\nSecure OAuth handling:\u003Cbr \u002F>\nToken exchange (authorization code to access\u002Frefresh tokens) is restricted to users with administrator-level permissions (manage_options). You must be logged in as an admin when completing the OAuth connection.\u003Cbr \u002F>\nTesting tools included:\u003Cbr \u002F>\nIncludes a built-in test email feature and an SMTP connection tester to help verify configuration.\u003Cbr \u002F>\nLogging and debugging:\u003Cbr \u002F>\nEmail activity and debug information are stored in custom database tables for troubleshooting and monitoring.\u003C\u002Fp>\n\u003Cp>Security and stored secrets\u003C\u002Fp>\n\u003Cp>This plugin stores SMTP passwords, OAuth client secrets, refresh tokens, and access tokens in the WordPress options table, using the same approach as most WordPress settings. These values are not encrypted at rest.\u003C\u002Fp>\n\u003Cp>Anyone with access to the database, a full site backup, or an administrator account could potentially view this information. It’s recommended to use strong admin credentials, secure hosting, and limit your app permissions to only what is required.\u003C\u002Fp>\n\u003Cp>This plugin is not affiliated with or endorsed by Microsoft. Microsoft, Microsoft 365, Azure, Office, and related names are trademarks of Microsoft Corporation. These names are used only to describe compatibility and technical functionality.\u003C\u002Fp>\n\u003Cp>Do not use Microsoft or related logos, branding, or visual assets in your plugin icon, banner, or screenshots on WordPress.org. Use your own branding and neutral visuals.\u003C\u002Fp>\n\u003Cp>Third-party services\u003C\u002Fp>\n\u003Cp>This plugin connects to external services only when required for email delivery or authentication. It does not send general site traffic or unrelated data to third parties.\u003C\u002Fp>\n\u003Cp>Microsoft identity platform (OAuth2) — login.microsoftonline.com\u003C\u002Fp>\n\u003Cp>What it is\u003Cbr \u002F>\nThis is Microsoft’s OAuth2 authentication service (also known as the Microsoft Identity Platform or Entra ID). It is used when you connect your account using OAuth.\u003C\u002Fp>\n\u003Cp>What it is used for\u003C\u002Fp>\n\u003Cp>Signing in through Microsoft\u003Cbr \u002F>\nExchanging authorization codes for access and refresh tokens\u003Cbr \u002F>\nRefreshing expired access tokens\u003C\u002Fp>\n\u003Cp>What data is sent and when\u003C\u002Fp>\n\u003Cp>During login (via browser): client ID, redirect URI, requested scopes (such as Mail.Send, User.Read), and a state parameter for security\u003Cbr \u002F>\nDuring token exchange (server-side): authorization code, client ID, client secret, redirect URI, grant type, and scopes\u003C\u002Fp>\n\u003Cp>Terms\u003Cbr \u002F>\nhttps:\u002F\u002Fwww.microsoft.com\u002Fservicesagreement\u003C\u002Fp>\n\u003Cp>Privacy\u003Cbr \u002F>\nhttps:\u002F\u002Fprivacy.microsoft.com\u002Fprivacystatement\u003C\u002Fp>\n\u003Cp>Microsoft Graph API — graph.microsoft.com\u003C\u002Fp>\n\u003Cp>What it is\u003Cbr \u002F>\nMicrosoft’s API for accessing Microsoft 365 services, including sending emails.\u003C\u002Fp>\n\u003Cp>What it is used for\u003Cbr \u002F>\nSending emails through the Graph API (\u002Fv1.0\u002Fme\u002FsendMail).\u003C\u002Fp>\n\u003Cp>What data is sent and when\u003Cbr \u002F>\nWhen an email is sent (including test emails), the plugin makes a secure HTTPS request that includes:\u003C\u002Fp>\n\u003Cp>An OAuth access token\u003Cbr \u002F>\nEmail details such as recipients, subject, message body, and optional Cc\u002FBcc\u002FReply-To\u003Cbr \u002F>\nAttachments or inline images (within API limits)\u003C\u002Fp>\n\u003Cp>Terms\u003Cbr \u002F>\nhttps:\u002F\u002Fwww.microsoft.com\u002Fservicesagreement\u003C\u002Fp>\n\u003Cp>Privacy\u003Cbr \u002F>\nhttps:\u002F\u002Fprivacy.microsoft.com\u002Fprivacystatement\u003C\u002Fp>\n\u003Cp>Note: Use of Microsoft APIs is also subject to Microsoft’s developer and product terms. Refer to https:\u002F\u002Fwww.microsoft.com\u002Flegal\u002F\u003Cbr \u002F>\n for details.\u003C\u002Fp>\n\u003Cp>User-configured SMTP server\u003C\u002Fp>\n\u003Cp>What it is\u003Cbr \u002F>\nAn SMTP server that you configure (for example, your hosting provider, Microsoft 365, Google Workspace, or another email service).\u003C\u002Fp>\n\u003Cp>What it is used for\u003Cbr \u002F>\nSending emails using your SMTP credentials.\u003C\u002Fp>\n\u003Cp>What data is sent and when\u003Cbr \u002F>\nWhenever an email is sent (including test emails), the plugin transmits:\u003C\u002Fp>\n\u003Cp>SMTP credentials (if configured)\u003Cbr \u002F>\nEmail content such as recipients, subject, and message body\u003C\u002Fp>\n\u003Cp>This plugin does not control or manage the infrastructure of your SMTP provider.\u003C\u002Fp>\n\u003Cp>Terms and privacy\u003Cbr \u002F>\nYou are responsible for reviewing the terms and privacy policy of your email provider. This plugin does not replace or override those agreements.\u003C\u002Fp>\n","SMTP or Microsoft Graph OAuth mail for WordPress. Full wp_mail replacement with logging, queue, and SMTP\u002Femail test tools.",10,366,"2026-07-20T14:33:00.000Z","6.2","",[51,19,52,53,54],"graph-api","oauth","outlook-smtp","smtp","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fvr-smtp-mailer\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvr-smtp-mailer.2.0.zip",{"slug":58,"name":59,"version":60,"author":61,"author_profile":62,"description":63,"short_description":64,"active_installs":11,"downloaded":65,"rating":11,"num_ratings":11,"last_updated":66,"tested_up_to":14,"requires_at_least":48,"requires_php":16,"tags":67,"homepage":49,"download_link":70,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"dixonsmtp-for-outlook-microsoft-365","DixonSMTP for Outlook & Microsoft 365","1.0.0","Dixon Cherian","https:\u002F\u002Fprofiles.wordpress.org\u002Fdixonem\u002F","\u003Cp>WordPress’ default PHP mail() delivery is frequently blocked or spam-foldered. \u003Cstrong>DixonSMTP for Outlook & Microsoft 365\u003C\u002Fstrong> routes every email your site sends (core, WooCommerce, WPForms, Contact Form 7, Gravity Forms, and anything else using \u003Ccode>wp_mail()\u003C\u002Fcode>) through Microsoft’s SMTP servers — authenticated, encrypted, and deliverable.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>100% free.\u003C\u002Fstrong> No premium upsell, no paid tiers, no feature gating.\u003C\u002Fp>\n\u003Ch4>Why OAuth 2.0?\u003C\u002Fh4>\n\u003Cp>Microsoft has \u003Cstrong>deprecated Basic Authentication\u003C\u002Fstrong> for Exchange Online and is progressively disabling password-based SMTP AUTH (new Microsoft 365 tenants have it off by default). OAuth 2.0 (“Modern Authentication”) is the supported, secure path forward — which is why this plugin is \u003Cstrong>OAuth-only\u003C\u002Fstrong> by design. It implements the full Microsoft identity platform authorization code flow with automatic token refresh, so you sign in once and it keeps working.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>OAuth 2.0 (Modern Auth)\u003C\u002Fstrong> for Microsoft 365 \u002F Entra ID — authorization code flow, automatic access-token refresh, encrypted token storage\u003C\u002Fli>\n\u003Cli>From Email \u002F From Name with optional force-override (recommended — Microsoft rejects mismatched senders)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Test email tool\u003C\u002Fstrong> with a full SMTP debug transcript\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email log\u003C\u002Fstrong> (last 10–500 emails, configurable) with status and error details in a custom table\u003C\u002Fli>\n\u003Cli>Optional \u003Cstrong>fallback to the default PHP mailer\u003C\u002Fstrong> when SMTP fails\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Failure notifications\u003C\u002Fstrong> to the site admin after repeated errors (rate-limited)\u003C\u002Fli>\n\u003Cli>Debug mode compatible with \u003Ccode>WP_DEBUG_LOG\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Multisite compatible (network activation supported; settings are per-site)\u003C\u002Fli>\n\u003Cli>Secrets (client secret, OAuth tokens) stored \u003Cstrong>encrypted\u003C\u002Fstrong> (AES-256 keyed from your WordPress salts)\u003C\u002Fli>\n\u003Cli>Translation-ready, fully sanitized\u002Fescaped, capability + nonce protected\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Compatibility\u003C\u002Fh4>\n\u003Cp>Works with any plugin that sends mail through \u003Ccode>wp_mail()\u003C\u002Fcode>: WPForms, Contact Form 7, Gravity Forms, Ninja Forms, WooCommerce, Easy Digital Downloads, membership and newsletter plugins, etc.\u003C\u002Fp>\n\u003Ch3>Microsoft 365 \u002F Azure OAuth Setup\u003C\u002Fh3>\n\u003Cp>You need a (free) app registration in Microsoft Entra ID. One-time setup, about 5 minutes:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>1. Register the application\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Sign in to \u003Ca href=\"https:\u002F\u002Fentra.microsoft.com\" rel=\"nofollow ugc\">https:\u002F\u002Fentra.microsoft.com\u003C\u002Fa> (or the Azure Portal \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Microsoft Entra ID).\u003C\u002Fli>\n\u003Cli>Go to \u003Cstrong>Identity \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Applications \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> App registrations \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> New registration\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Name: e.g. \u003Ccode>WordPress SMTP\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>Supported account types:\n\u003Cul>\n\u003Cli>\u003Cem>Accounts in this organizational directory only\u003C\u002Fem> — single company tenant (most common; use your Tenant ID in the plugin).\u003C\u002Fli>\n\u003Cli>\u003Cem>Accounts in any organizational directory and personal Microsoft accounts\u003C\u002Fem> — needed for personal Outlook.com mailboxes (use \u003Ccode>common\u003C\u002Fcode> in the plugin).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Redirect URI: choose platform \u003Cstrong>Web\u003C\u002Fstrong> and paste the exact Redirect URI shown on the plugin’s \u003Cstrong>OAuth 2.0\u003C\u002Fstrong> tab\u003Cbr \u002F>\n(it looks like \u003Ccode>https:\u002F\u002Fyour-site.com\u002Fwp-json\u002Fdxn-outlook\u002Fv1\u002Fcallback\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Register\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>2. Collect the IDs\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>On the app’s \u003Cstrong>Overview\u003C\u002Fstrong> page copy the \u003Cstrong>Application (client) ID\u003C\u002Fstrong> and \u003Cstrong>Directory (tenant) ID\u003C\u002Fstrong> into the plugin’s OAuth tab.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>3. Create a client secret\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>Certificates & secrets \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> New client secret\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Choose an expiry (set a calendar reminder — you must rotate it before expiry!).\u003C\u002Fli>\n\u003Cli>Copy the secret \u003Cstrong>Value\u003C\u002Fstrong> (not the Secret ID) immediately — it is shown only once — and paste it into the plugin.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>4. Add API permissions\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>API permissions \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add a permission\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Choose \u003Cstrong>APIs my organization uses\u003C\u002Fstrong> and search for \u003Cstrong>Office 365 Exchange Online\u003C\u002Fstrong>\u003Cbr \u002F>\n(or use \u003Cem>Microsoft Graph \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Delegated\u003C\u002Fem> if \u003Ccode>SMTP.Send\u003C\u002Fcode> appears there in your tenant).\u003C\u002Fli>\n\u003Cli>Select \u003Cstrong>Delegated permissions \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> SMTP.Send\u003C\u002Fstrong>, then Add.\u003C\u002Fli>\n\u003Cli>\u003Ccode>offline_access\u003C\u002Fcode>, \u003Ccode>openid\u003C\u002Fcode>, \u003Ccode>profile\u003C\u002Fcode>, \u003Ccode>email\u003C\u002Fcode> are requested automatically at sign-in; no admin action usually needed. If your tenant requires it, click \u003Cstrong>Grant admin consent\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>5. Enable SMTP AUTH for the mailbox\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Even with OAuth, Exchange Online requires SMTP AUTH to be allowed for the sending mailbox:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Microsoft 365 admin center \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Cstrong>Users \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Active users \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>\u003C\u002Fstrong> \u003Cem>select user\u003C\u002Fem> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Cstrong>Mail \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Manage email apps\u003C\u002Fstrong> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> check \u003Cstrong>Authenticated SMTP\u003C\u002Fstrong>, or\u003C\u002Fli>\n\u003Cli>PowerShell: \u003Ccode>Set-CASMailbox -Identity user@domain.com -SmtpClientAuthenticationDisabled $false\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>6. Authorize the plugin\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Save the Client ID, Client Secret and Tenant ID on the plugin’s \u003Cstrong>OAuth 2.0\u003C\u002Fstrong> tab.\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Sign in with Microsoft & Authorize\u003C\u002Fstrong> and sign in with the mailbox that should send email.\u003C\u002Fli>\n\u003Cli>When you return, the status shows \u003Cem>Connected\u003C\u002Fem>. Send a test email.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to Microsoft services in order to authenticate and deliver email. No data is sent to the plugin author or any other third party.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Microsoft identity platform\u003C\u002Fstrong> (\u003Ccode>login.microsoftonline.com\u003C\u002Fcode>) — used for OAuth 2.0 sign-in and token refresh. Sends your Azure app Client ID, Client Secret, authorization codes and refresh tokens. Contacted when you click “Sign in with Microsoft” and automatically before sending when the access token needs refreshing.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Microsoft SMTP servers\u003C\u002Fstrong> (\u003Ccode>smtp.office365.com\u003C\u002Fcode> or the host you configure) — used to deliver email. Sends the email content, sender and recipient addresses, and an OAuth access token for authentication. Contacted on every outgoing email.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>These services are provided by Microsoft: \u003Ca href=\"https:\u002F\u002Fwww.microsoft.com\u002Flegal\u002Fterms-of-use\" rel=\"nofollow ugc\">Terms of Use\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fprivacy.microsoft.com\u002Fprivacystatement\" rel=\"nofollow ugc\">Privacy Statement\u003C\u002Fa>.\u003C\u002Fp>\n","Send WordPress emails reliably through Outlook.com \u002F Microsoft 365 SMTP with OAuth 2.0, email logging, and a built-in test tool.",36,"2026-07-21T16:06:00.000Z",[68,19,52,69,54],"email","outlook","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdixonsmtp-for-outlook-microsoft-365.1.0.0.zip",{"attackSurface":72,"codeSignals":141,"taintFlows":171,"riskAssessment":264,"analyzedAt":270},{"hooks":73,"ajaxHandlers":112,"restRoutes":138,"shortcodes":139,"cronEvents":140,"entryPointCount":84,"unprotectedCount":11},[74,80,85,90,94,98,101,104,108],{"type":75,"name":76,"callback":77,"file":78,"line":79},"action","admin_post_wbconn_auth","wbconn_auth_callback","includes\\admin\\integration\\auth-callback.php",4,{"type":75,"name":81,"callback":82,"priority":45,"file":83,"line":84},"fluentform_submission_inserted","wbconn_send_to_excel","includes\\modules\\fluentform\\class-fluentform-handler.php",8,{"type":75,"name":86,"callback":87,"file":88,"line":89},"admin_menu","wbconn_register_admin_menu","workbook-connector-for-microsoft-365.php",42,{"type":75,"name":91,"callback":92,"file":88,"line":93},"init","wbconn_load_all_classes",43,{"type":75,"name":95,"callback":96,"file":88,"line":97},"admin_init","wbconn_handle_auth_redirect",47,{"type":75,"name":91,"callback":99,"file":88,"line":100},"wbconn_save_api_credentials",50,{"type":75,"name":91,"callback":102,"file":88,"line":103},"load_css_and_js_files",51,{"type":75,"name":105,"callback":106,"file":88,"line":107},"admin_print_styles","wbconn_add_css_files",56,{"type":75,"name":109,"callback":110,"file":88,"line":111},"admin_print_scripts","wbconn_add_js_files",57,[113,118,121,123,127,129,132,135],{"action":114,"nopriv":115,"callback":114,"hasNonce":116,"hasCapCheck":116,"file":117,"line":84},"wbconn_save_feed",false,true,"includes\\admin\\feed\\feed-service.php",{"action":119,"nopriv":115,"callback":119,"hasNonce":116,"hasCapCheck":116,"file":117,"line":120},"wbconn_delete_feed",9,{"action":122,"nopriv":115,"callback":122,"hasNonce":116,"hasCapCheck":116,"file":117,"line":45},"wbconn_save_sheet_details",{"action":124,"nopriv":115,"callback":124,"hasNonce":116,"hasCapCheck":115,"file":125,"line":126},"wbconn_handle_connect","includes\\admin\\integration\\auth-actions.php",7,{"action":128,"nopriv":115,"callback":128,"hasNonce":116,"hasCapCheck":115,"file":125,"line":84},"wbconn_handle_deactivate",{"action":130,"nopriv":115,"callback":130,"hasNonce":116,"hasCapCheck":116,"file":88,"line":131},"wbconn_fetch_excels",44,{"action":133,"nopriv":115,"callback":133,"hasNonce":116,"hasCapCheck":116,"file":88,"line":134},"wbconn_fetch_worksheets",45,{"action":136,"nopriv":115,"callback":136,"hasNonce":116,"hasCapCheck":116,"file":88,"line":137},"wbconn_fetch_tables",46,[],[],[],{"dangerousFunctions":142,"sqlUsage":143,"outputEscaping":152,"fileOperations":11,"externalRequests":79,"nonceChecks":45,"capabilityChecks":169,"bundledLibraries":170},[],{"prepared":144,"raw":145,"locations":146},20,2,[147,150],{"file":148,"line":45,"context":149},"includes\\admin\\feed\\feeds-tab.php","$wpdb->get_results() with variable interpolation",{"file":148,"line":151,"context":149},123,{"escaped":153,"rawEcho":126,"locations":154},119,[155,159,161,162,163,165,168],{"file":156,"line":157,"context":158},"includes\\admin\\integration\\class-fluentform-integration-settings.php",29,"raw output",{"file":156,"line":160,"context":158},38,{"file":156,"line":137,"context":158},{"file":156,"line":100,"context":158},{"file":156,"line":164,"context":158},54,{"file":166,"line":167,"context":158},"includes\\admin\\settings-page.php",26,{"file":166,"line":33,"context":158},6,[],[172,189,207,219,233,242],{"entryPoint":173,"graph":174,"unsanitizedCount":11,"severity":188},"wbconn_save_feed (includes\\admin\\feed\\feed-service.php:12)",{"nodes":175,"edges":186},[176,181],{"id":177,"type":178,"label":179,"file":117,"line":180},"n0","source","$_POST",24,{"id":182,"type":183,"label":184,"file":117,"line":160,"wp_function":185},"n1","sink","get_var() [SQLi]","get_var",[187],{"from":177,"to":182,"sanitized":116},"low",{"entryPoint":190,"graph":191,"unsanitizedCount":11,"severity":188},"wbconn_save_sheet_details (includes\\admin\\feed\\feed-service.php:99)",{"nodes":192,"edges":204},[193,195,197,199],{"id":177,"type":178,"label":179,"file":117,"line":194},110,{"id":182,"type":183,"label":184,"file":117,"line":196,"wp_function":185},111,{"id":198,"type":178,"label":179,"file":117,"line":194},"n2",{"id":200,"type":183,"label":201,"file":117,"line":202,"wp_function":203},"n3","get_row() [SQLi]",122,"get_row",[205,206],{"from":177,"to":182,"sanitized":116},{"from":198,"to":200,"sanitized":116},{"entryPoint":208,"graph":209,"unsanitizedCount":11,"severity":188},"\u003Cfeed-service> (includes\\admin\\feed\\feed-service.php:0)",{"nodes":210,"edges":216},[211,213,214,215],{"id":177,"type":178,"label":212,"file":117,"line":180},"$_POST (x2)",{"id":182,"type":183,"label":184,"file":117,"line":160,"wp_function":185},{"id":198,"type":178,"label":179,"file":117,"line":194},{"id":200,"type":183,"label":201,"file":117,"line":202,"wp_function":203},[217,218],{"from":177,"to":182,"sanitized":116},{"from":198,"to":200,"sanitized":116},{"entryPoint":220,"graph":221,"unsanitizedCount":11,"severity":188},"handle_callback (includes\\core\\class-auth.php:33)",{"nodes":222,"edges":231},[223,227],{"id":177,"type":178,"label":224,"file":225,"line":226},"$_GET (x2)","includes\\core\\class-auth.php",63,{"id":182,"type":183,"label":228,"file":225,"line":229,"wp_function":230},"update_option() [Settings Manipulation]",88,"update_option",[232],{"from":177,"to":182,"sanitized":116},{"entryPoint":234,"graph":235,"unsanitizedCount":11,"severity":188},"\u003Cclass-auth> (includes\\core\\class-auth.php:0)",{"nodes":236,"edges":240},[237,239],{"id":177,"type":178,"label":238,"file":225,"line":226},"$_GET (x4)",{"id":182,"type":183,"label":228,"file":225,"line":229,"wp_function":230},[241],{"from":177,"to":182,"sanitized":116},{"entryPoint":243,"graph":244,"unsanitizedCount":79,"severity":263},"\u003Cedit> (includes\\admin\\feed\\edit.php:0)",{"nodes":245,"edges":259},[246,248,249,250,251,254],{"id":177,"type":178,"label":224,"file":247,"line":169},"includes\\admin\\feed\\edit.php",{"id":182,"type":183,"label":201,"file":247,"line":120,"wp_function":203},{"id":198,"type":178,"label":224,"file":247,"line":169},{"id":200,"type":183,"label":184,"file":247,"line":103,"wp_function":185},{"id":252,"type":178,"label":253,"file":247,"line":126},"n4","$_GET (x12)",{"id":255,"type":183,"label":256,"file":247,"line":257,"wp_function":258},"n5","echo() [XSS]",78,"echo",[260,261,262],{"from":177,"to":182,"sanitized":115},{"from":198,"to":200,"sanitized":115},{"from":252,"to":255,"sanitized":116},"high",{"summary":265,"deductions":266},"The \"workbook-connector-for-microsoft-365\" plugin, at version 1.0.2, exhibits a generally good security posture based on the static analysis.  The plugin demonstrates strong adherence to secure coding practices, with a significant percentage of SQL queries using prepared statements and a high rate of proper output escaping.  The absence of dangerous functions, file operations, and a clean vulnerability history further contribute to this positive assessment.  The attack surface, while consisting of 8 AJAX handlers, is noteworthy for having no identified unprotected entry points, indicating proper authentication and authorization checks are in place for these handlers.\n\nHowever, there is a single flow identified in the taint analysis with an unsanitized path, flagged as high severity. This represents a potential vulnerability where user-supplied input might not be adequately validated before being used in a sensitive operation, which could lead to unexpected behavior or potentially more severe issues if exploited in conjunction with other factors.  While the plugin has no known CVEs and a clean history, this identified high-severity taint flow warrants attention and investigation.  The presence of external HTTP requests, while not inherently a vulnerability, can sometimes introduce risks if the target endpoints are compromised or if data is transmitted insecurely.",[267],{"reason":268,"points":269},"High severity taint flow with unsanitized path",12,"2026-03-17T06:54:04.733Z",{"wat":272,"direct":283},{"assetPaths":273,"generatorPatterns":277,"scriptPaths":278,"versionParams":279},[274,275,276],"\u002Fwp-content\u002Fplugins\u002Fworkbook-connector-for-microsoft-365\u002Fassets\u002Fcss\u002Fwbconn-admin-style.css","\u002Fwp-content\u002Fplugins\u002Fworkbook-connector-for-microsoft-365\u002Fassets\u002Fjs\u002Fwbconn-admin-script.js","\u002Fwp-content\u002Fplugins\u002Fworkbook-connector-for-microsoft-365\u002Fassets\u002Fjs\u002Fwbconn-fluentform-handler.js",[],[275,276],[280,281,282],"workbook-connector-for-microsoft-365\u002Fassets\u002Fcss\u002Fwbconn-admin-style.css?ver=","workbook-connector-for-microsoft-365\u002Fassets\u002Fjs\u002Fwbconn-admin-script.js?ver=","workbook-connector-for-microsoft-365\u002Fassets\u002Fjs\u002Fwbconn-fluentform-handler.js?ver=",{"cssClasses":284,"htmlComments":285,"htmlAttributes":286,"restEndpoints":287,"jsGlobals":292,"shortcodeOutput":294},[],[],[],[288,289,290,291],"\u002Fwp-json\u002Fwbconn\u002Fv1\u002Ffeed\u002Fsave","\u002Fwp-json\u002Fwbconn\u002Fv1\u002Ffeed\u002Fdelete","\u002Fwp-json\u002Fwbconn\u002Fv1\u002Ffeed\u002Fget","\u002Fwp-json\u002Fwbconn\u002Fv1\u002Fsettings\u002Fsave",[293],"wbconn_ajax_object",[],{"error":116,"url":296,"statusCode":297,"statusMessage":298,"message":298},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fworkbook-connector-for-microsoft-365\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":300,"versions":301},5,[302,309,314,321,328],{"version":303,"download_url":304,"svn_tag_url":305,"released_at":26,"has_diff":115,"diff_files_changed":306,"diff_lines":26,"trac_diff_url":307,"vulnerabilities":308,"is_current":115},"1.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fworkbook-connector-for-microsoft-365.1.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fworkbook-connector-for-microsoft-365\u002Ftags\u002F1.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fworkbook-connector-for-microsoft-365%2Ftags%2F1.0.5&new_path=%2Fworkbook-connector-for-microsoft-365%2Ftags%2F1.2",[],{"version":6,"download_url":24,"svn_tag_url":310,"released_at":26,"has_diff":115,"diff_files_changed":311,"diff_lines":26,"trac_diff_url":312,"vulnerabilities":313,"is_current":116},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fworkbook-connector-for-microsoft-365\u002Ftags\u002F1.0.5\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fworkbook-connector-for-microsoft-365%2Ftags%2F1.0.4&new_path=%2Fworkbook-connector-for-microsoft-365%2Ftags%2F1.0.5",[],{"version":315,"download_url":316,"svn_tag_url":317,"released_at":26,"has_diff":115,"diff_files_changed":318,"diff_lines":26,"trac_diff_url":319,"vulnerabilities":320,"is_current":115},"1.0.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fworkbook-connector-for-microsoft-365.1.0.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fworkbook-connector-for-microsoft-365\u002Ftags\u002F1.0.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fworkbook-connector-for-microsoft-365%2Ftags%2F1.0.3&new_path=%2Fworkbook-connector-for-microsoft-365%2Ftags%2F1.0.4",[],{"version":322,"download_url":323,"svn_tag_url":324,"released_at":26,"has_diff":115,"diff_files_changed":325,"diff_lines":26,"trac_diff_url":326,"vulnerabilities":327,"is_current":115},"1.0.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fworkbook-connector-for-microsoft-365.1.0.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fworkbook-connector-for-microsoft-365\u002Ftags\u002F1.0.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fworkbook-connector-for-microsoft-365%2Ftags%2F1.0.2&new_path=%2Fworkbook-connector-for-microsoft-365%2Ftags%2F1.0.3",[],{"version":329,"download_url":330,"svn_tag_url":331,"released_at":26,"has_diff":115,"diff_files_changed":332,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":333,"is_current":115},"1.0.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fworkbook-connector-for-microsoft-365.1.0.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fworkbook-connector-for-microsoft-365\u002Ftags\u002F1.0.2\u002F",[],[]]