WP Simple Spreadsheet Fetcher for Google Security & Risk Analysis

wordpress.org/plugins/wp-simple-spreadsheet-fetcher-for-google

This is the simple plugin to fetch data from Google Sheets and display it on your website. This plugin only works with Block Editor, doesn't supp …

100 active installs v0.7.9 PHP + WP 5.3+ Updated Dec 15, 2020
apifetchergoogle-sheets
84
B · Generally Safe
CVEs total1
Unpatched0
Last CVEJan 5, 2020
Safety Verdict

Is WP Simple Spreadsheet Fetcher for Google Safe to Use in 2026?

Mostly Safe

Score 84/100

WP Simple Spreadsheet Fetcher for Google is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVELast CVE: Jan 5, 2020Updated 5yr ago
Risk Assessment

The "wp-simple-spreadsheet-fetcher-for-google" plugin, version 0.7.9, exhibits a generally good security posture due to its limited attack surface and diligent use of prepared statements for SQL queries. The static analysis shows no readily exploitable entry points like AJAX handlers, REST API routes, or shortcodes without authentication. Furthermore, the plugin demonstrates strong output escaping practices, with over 90% of outputs properly sanitized, and includes nonce checks and a single capability check, which are positive security measures. The absence of critical or high-severity taint flows is also encouraging.

Key Concerns

  • Vulnerability history indicates past CSRF issues
  • File operations without context
  • Bundled library Guzzle may be outdated
  • Taint analysis shows unsanitized paths
Vulnerabilities
1

WP Simple Spreadsheet Fetcher for Google Security Vulnerabilities

CVEs by Year

1 CVE in 2020
2020
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

WP Simple Spreadsheet Fetcher for Google < 0.3.7 - Cross-Site Request Forgery

Jan 5, 2020 Patched in 0.3.7 (1479d)
Code Analysis
Analyzed Mar 16, 2026

WP Simple Spreadsheet Fetcher for Google Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
27 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

93% escaped29 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
render_settings (src\App\Setup\ApiSettingScreen.php:72)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Simple Spreadsheet Fetcher for Google Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionrest_api_initsrc\App\RestAPI\sheets\EntryPoint.php:20
actionwp_headsrc\App\RestAPI\sheets\EntryPoint.php:21
actionadmin_headsrc\App\RestAPI\sheets\EntryPoint.php:22
actionadmin_menusrc\App\Setup\ApiSettingScreen.php:10
actionadmin_enqueue_scriptssrc\App\Setup\ApiSettingScreen.php:11
actionblock_categoriessrc\App\Setup\BlockRegistration.php:17
actioninitsrc\App\Setup\BlockRegistration.php:18
actionwp_enqueue_scriptssrc\App\Setup\BlockRegistration.php:19
actionadmin_enqueue_scriptssrc\App\Setup\BlockRegistration.php:20
Maintenance & Trust

WP Simple Spreadsheet Fetcher for Google Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedDec 15, 2020
PHP min version
Downloads7K

Community Trust

Rating82/100
Number of ratings7
Active installs100
Developer Profile

WP Simple Spreadsheet Fetcher for Google Developer Profile

Naoki Ohashi

2 plugins · 100 total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
1479 days
View full developer profile
Detection Fingerprints

How We Detect WP Simple Spreadsheet Fetcher for Google

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-simple-spreadsheet-fetcher-for-google/build/index.asset.php/wp-content/plugins/wp-simple-spreadsheet-fetcher-for-google/src/assets/css/admin.css/wp-content/plugins/wp-simple-spreadsheet-fetcher-for-google/src/assets/css/editor.css/wp-content/plugins/wp-simple-spreadsheet-fetcher-for-google/src/assets/css/style.css/wp-content/plugins/wp-simple-spreadsheet-fetcher-for-google/build/index.js
Script Paths
/wp-content/plugins/wp-simple-spreadsheet-fetcher-for-google/build/index.js
Version Parameters
wp-simple-spreadsheet-fetcher-for-google/css/admin.css?ver=wp-simple-spreadsheet-fetcher-for-google/src/assets/css/editor.css?ver=wp-simple-spreadsheet-fetcher-for-google/src/assets/css/style.css?ver=wp-simple-spreadsheet-fetcher-for-google/build/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
api-keywp2s2fg_api_spreadsheetId_form_labelsuccesswarn
Data Attributes
id="wp2s2fg_api_spreadsheetId_form"data-wp2s2fg-celldata-wp2s2fg-sheetdata-wp2s2fg-spreadsheetdata-wp2s2fg-api-keydata-wp2s2fg-columns+1 more
JS Globals
wp.blockswp.elementwp.i18nwp.editorwp.componentswp.data+3 more
REST Endpoints
/wp-json/wp2s2fg/v1/spreadsheet/wp-json/wp2s2fg/v1/fetch
Shortcode Output
[wp_simple_spreadsheet_fetcher][wp_simple_spreadsheet_fetcher_config]
FAQ

Frequently Asked Questions about WP Simple Spreadsheet Fetcher for Google