
Custom GlotPress Source Security & Risk Analysis
wordpress.org/plugins/custom-glotpress-sourceAllows to manage translations from a custom GlotPress install.
Is Custom GlotPress Source Safe to Use in 2026?
Generally Safe
Score 100/100Custom GlotPress Source has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-glotpress-source" plugin version 1.5.3 presents a generally positive security posture, with no recorded vulnerabilities or high-severity code signals. The absence of known CVEs and the use of prepared statements for all SQL queries are strong indicators of good security development practices. The plugin also demonstrates awareness of security by implementing nonce checks and file operations, and it doesn't appear to bundle outdated libraries.
However, there are notable concerns that temper this positive outlook. The most significant finding is that 100% of the eight identified output operations are not properly escaped. This creates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the plugin's output, potentially affecting users. Additionally, the plugin makes two external HTTP requests, and while the static analysis doesn't indicate unsanitized inputs leading to these requests, it's a potential vector for man-in-the-middle attacks or other vulnerabilities if not handled securely.
While the plugin has a clean vulnerability history, this doesn't negate the risks identified in the static analysis. The lack of properly escaped output is a critical flaw that requires immediate attention. The plugin's strength lies in its minimal attack surface and adherence to SQL prepared statements, but the unescaped output represents a substantial weakness that could be exploited by attackers. It's crucial to address the output escaping issue to improve the overall security of the plugin.
Key Concerns
- All output operations lack proper escaping
- External HTTP requests are present
Custom GlotPress Source Security Vulnerabilities
Custom GlotPress Source Code Analysis
Output Escaping
Custom GlotPress Source Attack Surface
WordPress Hooks 6
Maintenance & Trust
Custom GlotPress Source Maintenance & Trust
Maintenance Signals
Community Trust
Custom GlotPress Source Alternatives
GlotPress Notify
glotpress-notify
notify WordPress users when new GlotPress translations strings are awaiting review
Performant Translations
performant-translations
Making internationalization/localization in WordPress faster than ever before.
Preferred Languages
preferred-languages
Choose languages for displaying WordPress in, in order of preference.
Phrase TMS Integration for WordPress
memsource-connector
We’re transforming language technology, opening the door to global business so you can reach more people, make deeper connections, and drive growth.
Localize WordPress
localize
Easily switch to any localization from GlotPress
Custom GlotPress Source Developer Profile
12 plugins · 2K total installs
How We Detect Custom GlotPress Source
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-glotpress-source/js/script.js/wp-content/plugins/custom-glotpress-source/js/script.jscustom-glotpress-source/js/script.js?ver=HTML / DOM Fingerprints
Custom_GlotPress_Source