
Connect Elementor Forms to Google Sheets Addon Security & Risk Analysis
wordpress.org/plugins/wpsyncsheets-elementorEasily connect Elementor Pro Forms to Google Sheets and automatically sync form entries in real-time—no coding required, simple, secure, and one-time …
Is Connect Elementor Forms to Google Sheets Addon Safe to Use in 2026?
Generally Safe
Score 100/100Connect Elementor Forms to Google Sheets Addon has a strong security track record. Known vulnerabilities have been patched promptly.
The "wpsyncsheets-elementor" plugin v1.5.9.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and implements a significant number of nonce and capability checks. The absence of critical or high severity taint flows is also a strength. However, there are notable concerns, primarily stemming from its attack surface. The plugin exposes two AJAX handlers, one of which lacks authentication checks, presenting a direct entry point for unauthorized actions. Additionally, the taint analysis revealed two flows with unsanitized paths, although these did not escalate to critical or high severity. The vulnerability history shows a single low-severity CVE related to a dependency on a vulnerable third-party component. While this CVE is currently patched, the pattern suggests a potential future risk if dependencies are not diligently managed.
Overall, the plugin has strengths in secure database interaction and authorization checks. However, the unprotected AJAX handler is a significant weakness that could allow unauthenticated users to trigger potentially harmful actions. The unsanitized path flows, though not severe, indicate areas where input validation could be improved. The plugin's reliance on third-party components, as evidenced by its past vulnerability, requires ongoing vigilance. A balanced conclusion is that while the core implementation shows care, the exposure of an unauthenticated AJAX endpoint warrants immediate attention to mitigate potential exploitation.
Key Concerns
- AJAX handler without authentication check
- Flows with unsanitized paths
- Low severity CVE related to dependency
Connect Elementor Forms to Google Sheets Addon Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPSyncSheets Lite For Elementor – Elementor Pro Form Google Spreadsheet Addon <= 1.4 - Running Vulnerable Dependencies
Connect Elementor Forms to Google Sheets Addon Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Connect Elementor Forms to Google Sheets Addon Attack Surface
AJAX Handlers 2
WordPress Hooks 16
Maintenance & Trust
Connect Elementor Forms to Google Sheets Addon Maintenance & Trust
Maintenance Signals
Community Trust
Connect Elementor Forms to Google Sheets Addon Alternatives
FormsDB – Save Elementor Forms to Google Sheets & Post Type
sb-elementor-contact-form-db
Connect Elementor forms with Google Sheets to sync form entries, or save form submissions in any post type using Elementor Pro or Hello Plus forms.
GSheetConnector for Elementor Forms – Sync Elementor Forms to Google Sheets
gsheetconnector-for-elementor-forms
Sync Elementor Forms and MetForm to Google Sheets in real-time with secure Google Sheets integration and automatic form submission sync.
Integration Sendy for Elementor
integration-sendy-elementor
Easily connect Elementor Pro forms to Sendy and automatically grow your email list with just a few clicks—no third-party tools required.
EntryDashboard – Database Addon & Sync for WPForms, CF7, Elementor & More
entries-manager
Saves, manages, and sync all form submissions to your WordPress database. The most powerful Database Addon for WPForms, Contact Form 7, and Elementor …
iaRe CRM
iare-crm
Integração completa com o iaRe CRM para captura e gerenciamento de leads com suporte nativo do Elementor.
Connect Elementor Forms to Google Sheets Addon Developer Profile
6 plugins · 2K total installs
How We Detect Connect Elementor Forms to Google Sheets Addon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpsyncsheets-elementor/feedback/js/admin-feedback.js/wp-content/plugins/wpsyncsheets-elementor/feedback/css/admin-feedback.csswpsse-feedback-script?cswpsse-feedback-style?sHTML / DOM Fingerprints
wpsse-deactivation-containerwpsse-deactivation-responseid="wpsse-deactivate-feedback-dialog-wrapper"