Connect Elementor Forms to Google Sheets Addon Security & Risk Analysis

wordpress.org/plugins/wpsyncsheets-elementor

Easily connect Elementor Pro Forms to Google Sheets and automatically sync form entries in real-time—no coding required, simple, secure, and one-time …

800 active installs v1.5.9.3 PHP 5.6+ WP 5.3+ Updated Dec 8, 2025
elementorform-integrationform-syncgoogle-sheetslead-collection
100
A · Safe
CVEs total1
Unpatched0
Last CVEJan 17, 2025
Safety Verdict

Is Connect Elementor Forms to Google Sheets Addon Safe to Use in 2026?

Generally Safe

Score 100/100

Connect Elementor Forms to Google Sheets Addon has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 17, 2025Updated 3mo ago
Risk Assessment

The "wpsyncsheets-elementor" plugin v1.5.9.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and implements a significant number of nonce and capability checks. The absence of critical or high severity taint flows is also a strength. However, there are notable concerns, primarily stemming from its attack surface. The plugin exposes two AJAX handlers, one of which lacks authentication checks, presenting a direct entry point for unauthorized actions. Additionally, the taint analysis revealed two flows with unsanitized paths, although these did not escalate to critical or high severity. The vulnerability history shows a single low-severity CVE related to a dependency on a vulnerable third-party component. While this CVE is currently patched, the pattern suggests a potential future risk if dependencies are not diligently managed.

Overall, the plugin has strengths in secure database interaction and authorization checks. However, the unprotected AJAX handler is a significant weakness that could allow unauthenticated users to trigger potentially harmful actions. The unsanitized path flows, though not severe, indicate areas where input validation could be improved. The plugin's reliance on third-party components, as evidenced by its past vulnerability, requires ongoing vigilance. A balanced conclusion is that while the core implementation shows care, the exposure of an unauthenticated AJAX endpoint warrants immediate attention to mitigate potential exploitation.

Key Concerns

  • AJAX handler without authentication check
  • Flows with unsanitized paths
  • Low severity CVE related to dependency
Vulnerabilities
1

Connect Elementor Forms to Google Sheets Addon Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Low
1

1 total CVE

WF-3a3fa988-6f0b-48d3-a946-0fc587858c9c-wpsyncsheets-elementorlow · 3.7Dependency on Vulnerable Third-Party Component

WPSyncSheets Lite For Elementor – Elementor Pro Form Google Spreadsheet Addon <= 1.4 - Running Vulnerable Dependencies

Jan 17, 2025 Patched in 1.4.1 (1d)
Code Analysis
Analyzed Mar 16, 2026

Connect Elementor Forms to Google Sheets Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
52
111 escaped
Nonce Checks
5
Capability Checks
7
File Operations
1
External Requests
1
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared2 total queries

Output Escaping

68% escaped163 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
wpssle_review_notice_message (includes\class-wpssle-notifications.php:128)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Connect Elementor Forms to Google Sheets Addon Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 2

authwp_ajax_wpssle_reset_settingsincludes\class-wpssle-plugin-setting.php:133
authwp_ajax_install_and_activate_pluginincludes\class-wpssle-plugin-setting.php:141
WordPress Hooks 16
actionadmin_enqueue_scriptsfeedback\users-feedback.php:22
actionadmin_initfeedback\users-feedback.php:25
actionadmin_headfeedback\users-feedback.php:28
actionadmin_initincludes\class-wpssle-notifications.php:35
actionadmin_noticesincludes\class-wpssle-notifications.php:76
actionadmin_menuincludes\class-wpssle-plugin-setting.php:117
actionelementor/editor/after_enqueue_scriptsincludes\class-wpssle-plugin-setting.php:119
actionadmin_enqueue_scriptsincludes\class-wpssle-plugin-setting.php:121
actionadmin_enqueue_scriptsincludes\class-wpssle-plugin-setting.php:123
filterplugin_row_metaincludes\class-wpssle-plugin-setting.php:125
actionelementor_pro/initincludes\class-wpssle-plugin-setting.php:127
actionelementor/ajax/register_actionsincludes\class-wpssle-plugin-setting.php:129
actionelementor/editor/after_saveincludes\class-wpssle-plugin-setting.php:131
actioninitsrc\class-wpsyncsheetselementor.php:52
actioninitwpsyncsheets-lite-elementor.php:203
actionadmin_noticeswpsyncsheets-lite-elementor.php:252
Maintenance & Trust

Connect Elementor Forms to Google Sheets Addon Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 8, 2025
PHP min version5.6
Downloads67K

Community Trust

Rating100/100
Number of ratings6
Active installs800
Developer Profile

Connect Elementor Forms to Google Sheets Addon Developer Profile

Creative Werk Designs

6 plugins · 2K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
4 days
View full developer profile
Detection Fingerprints

How We Detect Connect Elementor Forms to Google Sheets Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpsyncsheets-elementor/feedback/js/admin-feedback.js/wp-content/plugins/wpsyncsheets-elementor/feedback/css/admin-feedback.css
Version Parameters
wpsse-feedback-script?cswpsse-feedback-style?s

HTML / DOM Fingerprints

CSS Classes
wpsse-deactivation-containerwpsse-deactivation-response
Data Attributes
id="wpsse-deactivate-feedback-dialog-wrapper"
FAQ

Frequently Asked Questions about Connect Elementor Forms to Google Sheets Addon