
WPGSI: Spreadsheet Integration Security & Risk Analysis
wordpress.org/plugins/wpgsiGoogle sheet two-way sync 🔄 WordPress | WooCommerce | Contact form 7 | DB table | Google sheet as a Table.
Is WPGSI: Spreadsheet Integration Safe to Use in 2026?
Generally Safe
Score 90/100WPGSI: Spreadsheet Integration has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wpgsi plugin v3.8.4 presents a mixed security posture with several concerning indicators. While it demonstrates some good practices like a substantial number of capability checks and a decent percentage of SQL queries using prepared statements, the significant number of AJAX handlers (50% of the total) lacking authorization checks is a major red flag, exposing a broad attack surface. The taint analysis further highlights this with a high number of flows with unsanitized paths, including 7 classified as high severity, indicating potential for data manipulation or unauthorized actions. The plugin's vulnerability history, with 5 known CVEs including two high-severity ones and a recent vulnerability in 2026, suggests a pattern of past security weaknesses that require careful monitoring. The presence of the `unserialize` function also warrants caution, as it can be a vector for deserialization vulnerabilities if not handled meticulously. Overall, the plugin has potential attack vectors due to unprotected entry points and identified high-severity taint flows, compounded by a history of past vulnerabilities, requiring diligent attention to security updates and a careful evaluation of its usage.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows found
- Known high severity vulnerabilities (historical)
- Known medium severity vulnerabilities (historical)
- Use of unserialize function
- SQL queries not using prepared statements
- Output not properly escaped
- Bundled outdated library (Freemius v1.0)
WPGSI: Spreadsheet Integration Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
WPGSI: Spreadsheet Integration <= 3.8.3 - Missing Authorization to Unauthenticated Arbitrary Post Creation and Deletion via Forged Base64 Token
Spreadsheet Integration <= 3.8.2 - Cross-Site Request Forgery to Arbitrary Post Publish
Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update
Spreadsheet Integration and Spreadsheet Integration Pro <= 3.5.0 - Reflected Cross-Site Scripting
Spreadsheet Integration and Spreadsheet Integration Pro <= 3.5.0 - Cross-Site Request Forgery
WPGSI: Spreadsheet Integration Release Timeline
WPGSI: Spreadsheet Integration Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WPGSI: Spreadsheet Integration Attack Surface
AJAX Handlers 5
REST API Routes 2
Shortcodes 1
WordPress Hooks 58
Scheduled Events 6
Maintenance & Trust
WPGSI: Spreadsheet Integration Maintenance & Trust
Maintenance Signals
Community Trust
WPGSI: Spreadsheet Integration Alternatives
Sheet Wise – WordPress to Google Sheets Automation for Forms, Users, Posts & WooCommerce
sheet-wise
Sync WordPress users, posts, comments, WooCommerce orders, and Contact Form 7 submissions to Google Sheets automatically.
Synchronizer Addon For WooCommerce to Google Spreadsheet
wpappsdev-gsheet-order-automation
This is a order automation system for WooCommerce and Google SpreadSheet.
Bit integrations – Easy Automator with no-code automation, integrate Webhook and automate 300+ Platform
bit-integrations
Perfect Automation and integration plugin: Connect 300+ platforms and automate CRM, Email marketing tools, Google Sheets, Contact forms, LMS and more
AFI – The Easiest Integration Plugin
advanced-form-integration
Connect any WordPress form or event to 200+ apps — no code. Send leads, orders, and signups to your CRM, email, or sheets in minutes.
ShopMagic for Contact Form 7 and WooCommerce
shopmagic-for-contact-form-7
Allows creating WooCommerce marketing automation and emailing WordPress users based on Contact Form 7 submission. You can use this Contact Form 7 inte …
WPGSI: Spreadsheet Integration Developer Profile
2 plugins · 2K total installs
How We Detect WPGSI: Spreadsheet Integration
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpgsi/admin/css/wpgsi-admin.css/wp-content/plugins/wpgsi/public/css/wpgsi-public.css/wp-content/plugins/wpgsi/public/js/wpgsi-public.js/wp-content/plugins/wpgsi/admin/js/wpgsi-admin.js/wp-content/plugins/wpgsi/public/js/wpgsi-public.jswpgsi/css/wpgsi-public.css?ver=wpgsi/css/wpgsi-admin.css?ver=wpgsi/js/wpgsi-public.js?ver=HTML / DOM Fingerprints
wpgsi_integration_title<!-- Bismilla Hir Rahmanir Raheem. --><!-- 29 Apr 2023 --><!-- Hello, Friend How are you doing? i am doing fine. --><!-- I know Golang, Python, PHP, Javascript, HTML & CSS. -->+10 morewpgsi_admin_object[wpgsi_integration]