
Connector for Gravity Forms and Google Sheets Security & Risk Analysis
wordpress.org/plugins/wp-gravity-forms-spreadsheetsGravity Forms Google Sheets Connector sends Gravity forms entries to Google Sheets.
Is Connector for Gravity Forms and Google Sheets Safe to Use in 2026?
Generally Safe
Score 95/100Connector for Gravity Forms and Google Sheets has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-gravity-forms-spreadsheets" v1.2.7 plugin presents a mixed security posture. While it demonstrates some good practices, such as a significant percentage of SQL queries using prepared statements and a substantial number of nonce and capability checks, there are notable areas of concern. The presence of one AJAX handler without authentication is a significant vulnerability, creating a direct entry point for potential attacks. This is further underscored by the taint analysis, which identified one flow with an unsanitized path of critical severity, indicating a high risk of exploiting this unprotected endpoint.
The vulnerability history reveals a pattern of past security weaknesses, including deserialization, open redirect, CSRF, and XSS. The fact that the last vulnerability was very recent (August 2025) and that there are currently no unpatched CVEs is positive, but the historical prevalence of various attack vectors suggests a need for continuous vigilance and thorough code auditing. The plugin also bundles the Select2 library, which, if not kept updated, could introduce further vulnerabilities.
In conclusion, while the plugin employs some robust security measures, the unprotected AJAX handler and the critical taint flow represent immediate risks that must be addressed. The plugin's history of diverse vulnerabilities necessitates a proactive approach to security. Addressing the identified unprotected entry point and ensuring all data flows are properly sanitized are paramount to improving its overall security. The bundled library also warrants attention regarding its version and potential for exploitation.
Key Concerns
- AJAX handler without auth check
- Taint flow with unsanitized path (high severity)
- Vulnerability history: 1 high, 3 medium CVEs
- Bundled library (Select2)
- SQL queries not using prepared statements (31%)
- Output escaping not properly handled (24%)
Connector for Gravity Forms and Google Sheets Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Connector for Gravity Forms and Google Sheets <= 1.2.6 - Unauthenticated PHP Object Injection
Connector for Gravity Forms and Google Sheets <= 1.2.4 - Open Redirect
Connector for Gravity Forms and Google Sheets <= 1.2.4 - Cross-Site Request Forgery
CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting
Connector for Gravity Forms and Google Sheets Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Connector for Gravity Forms and Google Sheets Attack Surface
AJAX Handlers 1
WordPress Hooks 29
Maintenance & Trust
Connector for Gravity Forms and Google Sheets Maintenance & Trust
Maintenance Signals
Community Trust
Connector for Gravity Forms and Google Sheets Alternatives
GSheetConnector for Gravity Forms – Send Gravity Forms Entries to Google Sheets in Real-Time
gsheetconnector-gravity-forms
Send Gravity Forms entries to Google Sheets in real-time. Automatically sync Gravity Forms submissions to Google Sheets with secure Google Sheets inte …
WPSyncSheets For Gravity Forms – Connect Gravity Forms to Google Sheets
wpsyncsheets-gravity-forms
Connect Gravity Forms with Google Sheets to export forms entries or save form submissions to Google Sheets in real-time.
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
Connector for Gravity Forms and Google Sheets Developer Profile
32 plugins · 105K total installs
How We Detect Connector for Gravity Forms and Google Sheets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-gravity-forms-spreadsheets/assets/js/gsheet.js/wp-content/plugins/wp-gravity-forms-spreadsheets/assets/css/gsheet.css/wp-content/plugins/wp-gravity-forms-spreadsheets/assets/js/gsheet.jswp-gravity-forms-spreadsheets/assets/css/gsheet.css?ver=wp-gravity-forms-spreadsheets/assets/js/gsheet.js?ver=HTML / DOM Fingerprints
vx_gsheet_sectionvx_gsheet_form_field<!-- vx_gsheet_section --><!-- vx_gsheet_form_field -->data-gsheet-iddata-field-idvx_gsheet_params