
AI Translate Security & Risk Analysis
wordpress.org/plugins/ai-translateAI Translate for WordPress & WooCommerce. Multilingual SEO with translated slugs & 35+ languages. Fast caching, unique Tone of Voice & low AI costs.
Is AI Translate Safe to Use in 2026?
Generally Safe
Score 100/100AI Translate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'ai-translate' plugin v2.2.9 exhibits a mixed security posture. While it demonstrates good practices in SQL query preparation (94%) and a clean vulnerability history with no recorded CVEs, significant concerns arise from its attack surface and taint analysis. A large portion of its AJAX handlers (12 out of 12) lack authentication checks, presenting a substantial entry point for unauthorized actions. Furthermore, the taint analysis reveals three high-severity flows with unsanitized paths, indicating potential vulnerabilities where user-controlled data could be mishandled. The plugin's reliance on file operations (14) and external HTTP requests (18) also warrant careful consideration in conjunction with these unsanitized paths.
Despite the absence of known vulnerabilities and proper nonce checks on most entry points, the high number of unprotected AJAX handlers and critical taint flows overshadow these strengths. The plugin needs immediate attention to address the security gaps in its AJAX endpoints and the identified high-severity taint issues. The lack of recorded vulnerabilities in its history might indicate a lack of rigorous security auditing or that past issues were minor and quickly addressed, but the current static analysis reveals pressing concerns that should be prioritized.
Key Concerns
- High number of AJAX handlers without auth checks
- High severity taint flows with unsanitized paths
- Unescaped output percentage is moderate
AI Translate Security Vulnerabilities
AI Translate Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
AI Translate Attack Surface
AJAX Handlers 12
REST API Routes 1
Shortcodes 2
WordPress Hooks 63
Scheduled Events 1
Maintenance & Trust
AI Translate Maintenance & Trust
Maintenance Signals
Community Trust
AI Translate Alternatives
Ailo – AI Slug Translator
haayal-ai-slug-translator
Automatically translate non-English slugs into clean, user-friendly English to improve sharing and SEO.
Linguise – AI Automatic Multilingual Translation
linguise
Linguise is a top-quality automatic AI translation with a front-end translation editor. 5' install, SEO-optimized translations, 85+ languages
Clonable – Translate Woocommerce / WordPress website. Multilingual in 5 minutes.
clonable
Seamlessly translate and maintain your multilingual websites. Speed up and simplify your internationalisation with Clonable.
ContentGecko Connector
contentgecko-connector
ContentGecko Connector syncs ContentGecko posts, products, and translations with WordPress securely.
Voxfor Multilanguage
voxfor-multilanguage
Professional multilingual WordPress plugin using the DeepL API. Transform your website into a global platform.
AI Translate Developer Profile
1 plugin · 40 total installs
How We Detect AI Translate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ai-translate/assets/css/styles.css/wp-content/plugins/ai-translate/assets/js/backend.js/wp-content/plugins/ai-translate/assets/js/frontend.js/wp-content/plugins/ai-translate/assets/js/scripts.js/wp-content/plugins/ai-translate/assets/js/frontend.jsai-translate/assets/css/styles.css?ver=ai-translate/assets/js/scripts.js?ver=ai-translate/assets/js/frontend.js?ver=ai-translate/assets/js/backend.js?ver=HTML / DOM Fingerprints
ai-translate-backendAI Translate: Translation is OFFAI Translate: Translation is ONai_translate_params/wp-json/ai-translate/v1/translate/wp-json/ai-translate/v1/get-languages