Bulglish Permalinks Security & Risk Analysis

wordpress.org/plugins/bulglish-permalinks

This plugin converts Bulgarian cyrillic characters in slugs and filenames to Latin characters, according to the official rules for transliteration.

3K active installs v1.4.2 PHP + WP 3.0.1+ Updated Jan 5, 2019
bulgarianbulgarian-permalinkcyrillicslugstransliteration
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bulglish Permalinks Safe to Use in 2026?

Generally Safe

Score 85/100

Bulglish Permalinks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'bulglish-permalinks' v1.4.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified entry points, including AJAX handlers, REST API routes, shortcodes, or cron events, significantly limits the potential attack surface. Furthermore, the code signals are exceptionally clean, with no dangerous functions, file operations, or external HTTP requests. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output. The vulnerability history is also clear, with no recorded CVEs, indicating a history of secure development or diligent patching by maintainers.

While the lack of identified vulnerabilities and a small attack surface are positive indicators, the analysis does highlight a complete absence of capability checks and nonce checks. Although there are no current entry points to exploit these, it suggests a lack of robust defense mechanisms that could become a concern if new functionalities are added without proper security considerations. The taint analysis shows no flows with unsanitized paths, which is excellent, but the total flows analyzed being 0 is a limitation of the analysis itself or indicative of very minimal code execution paths. Overall, this plugin appears to be very secure in its current state, with its primary weakness being the foundational security checks that are not utilized, which is a potential future risk rather than a current exploitability issue.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Bulglish Permalinks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bulglish Permalinks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Bulglish Permalinks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filtersanitize_titlebulglish-permalinks.php:54
filterwp_handle_upload_prefilterbulglish-permalinks.php:63
Maintenance & Trust

Bulglish Permalinks Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedJan 5, 2019
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings7
Active installs3K
Developer Profile

Bulglish Permalinks Developer Profile

Boyan Raichev

1 plugin · 3K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bulglish Permalinks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Bulglish Permalinks