
Translate WordPress Websites Globally with ConveyThis Translate Security & Risk Analysis
wordpress.org/plugins/conveythis-translateMake your WordPress site multilingual in minutes! 🌐 AI translations, 200+ languages, SEO & WooCommerce ready — no coding needed!
Is Translate WordPress Websites Globally with ConveyThis Translate Safe to Use in 2026?
Use With Caution
Score 67/100Translate WordPress Websites Globally with ConveyThis Translate has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'conveythis-translate' v269.6 plugin exhibits a mixed security posture. While it demonstrates good practices in areas like using prepared statements for SQL queries and generally proper output escaping, significant concerns arise from its attack surface and vulnerability history. The presence of unprotected AJAX handlers is a critical weakness, as these can be exploited by unauthenticated users to trigger potentially malicious actions. Taint analysis, while not revealing critical or high severity vulnerabilities in this specific scan, did identify flows with unsanitized paths, which could lead to issues if not handled carefully.
The plugin's vulnerability history is a major red flag. With five known CVEs, including one that is currently unpatched and rated as high severity, the plugin has a pattern of introducing security flaws. The common vulnerability types like Deserialization of Untrusted Data and Missing Authorization, coupled with Cross-site Scripting, suggest recurring issues that attackers could potentially leverage. The recentness of the last vulnerability further emphasizes the need for caution.
In conclusion, while the code shows some positive security implementations, the unprotected entry points and the history of significant vulnerabilities, especially the unpatched high-severity one, make this plugin a considerable risk. Users should exercise extreme caution and consider alternative solutions until all known vulnerabilities are addressed.
Key Concerns
- Unpatched high severity CVE
- Unprotected AJAX handlers
- Flows with unsanitized paths detected
- History of multiple CVEs
Translate WordPress Websites Globally with ConveyThis Translate Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
ConveyThis <= 269.1 - Missing Authorization
ConveyThis <= 269.2 - Missing Authorization
Language Translate Widget for WordPress – ConveyThis <= 269.1 - Authenticated (Administrator+) PHP Object Injection
Language Translate Widget for WordPress – ConveyThis <= 234 - Missing Authorization to Limited Option Update
Language Translate Widget for WordPress – ConveyThis <= 223 - Unauthenticated Stored Cross-Site Scripting via api_key
Translate WordPress Websites Globally with ConveyThis Translate Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Translate WordPress Websites Globally with ConveyThis Translate Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 48
Scheduled Events 1
Maintenance & Trust
Translate WordPress Websites Globally with ConveyThis Translate Maintenance & Trust
Maintenance Signals
Community Trust
Translate WordPress Websites Globally with ConveyThis Translate Alternatives
Best SEO iTranslator for WordPress
best-seo-itranslator-for-wordpress
Translate your blog in 40 languages and get tons of new traffic sources.
Translate WordPress with GTranslate
gtranslate
Translate WordPress with Google Translate multilanguage plugin to make your website multilingual. Complete multilingual SEO solution for WordPress.
Translate WordPress – Google Language Translator
google-language-translator
Translate WordPress with Google Language Translator multilanguage plugin which allows to insert Google Translate widget anywhere on your website.
Theme and plugin translation for Polylang (TTfP)
theme-translation-for-polylang
Theme and plugin translation using Polylang for WordPress. Extension for Polylang plugin.
Multilanguage by BestWebSoft – WordPress Translation Plugin and Language Switcher
multilanguage
The ultimate WordPress translation solution with built-in language translator. Create multilingual content, switch languages, and translate your entir …
Translate WordPress Websites Globally with ConveyThis Translate Developer Profile
1 plugin · 1K total installs
How We Detect Translate WordPress Websites Globally with ConveyThis Translate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/conveythis-translate/app/css/conveythis.css/wp-content/plugins/conveythis-translate/app/js/conveythis.js/wp-content/plugins/conveythis-translate/app/js/conveythis-admin.js/wp-content/plugins/conveythis-translate/app/js/conveythis-widget.js/wp-content/plugins/conveythis-translate/app/js/conveythis.js/wp-content/plugins/conveythis-translate/app/js/conveythis-admin.js/wp-content/plugins/conveythis-translate/app/js/conveythis-widget.jsconveythis-translate/app/css/conveythis.css?ver=conveythis-translate/app/js/conveythis.js?ver=conveythis-translate/app/js/conveythis-admin.js?ver=conveythis-translate/app/js/conveythis-widget.js?ver=HTML / DOM Fingerprints
conveythis-widgetct-switcher-containerct-flags<!-- ConveyThis Translate Settings --><!-- ConveyThis Admin Notices --><!-- ConveyThis Widget -->data-ct-api-keydata-ct-domain-idconveythis_settingsConveyThis/wp-json/conveythis/v1/settings/wp-json/conveythis/v1/translate[conveythis_switcher]