Cyr to Lat Reloaded – Transliteration of Links and File Names Security & Risk Analysis

wordpress.org/plugins/cyr-and-lat

Converts Cyrillic, Georgian, and Greek URLs and file names into readable Latin characters.

30K active installs v1.3.1 PHP 5.2+ WP 4.2+ Updated Jan 13, 2026
cyr-to-latcyrilliccyrillic-to-latinrus-to-lattransliteration
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cyr to Lat Reloaded – Transliteration of Links and File Names Safe to Use in 2026?

Generally Safe

Score 100/100

Cyr to Lat Reloaded – Transliteration of Links and File Names has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'cyr-and-lat' v1.3.1 plugin exhibits a strong security posture based on the provided static analysis. It boasts a zero attack surface for both AJAX and REST API interactions, and lacks shortcodes or cron events, significantly minimizing potential entry points. The code analysis reveals responsible use of dangerous functions and file operations, with a commendable 85% of output properly escaped. The presence of nonce checks is also a positive indicator of security awareness.

However, there are areas for improvement. A concerning 71% of SQL queries are not using prepared statements, which presents a moderate risk of SQL injection vulnerabilities if these queries handle user-supplied data without proper sanitization. The absence of capability checks on any part of the code, combined with the use of raw SQL queries, raises concerns about privilege escalation or unauthorized data access if any part of the plugin's logic were to be triggered in an unexpected way or if user input were to influence the SQL execution.

The plugin's vulnerability history is clean, with zero known CVEs. This, coupled with the clean taint analysis, suggests that historically, the plugin has not been a source of exploitable vulnerabilities. While the lack of past issues is reassuring, it does not negate the risks identified in the current static analysis, particularly concerning the SQL query handling. The plugin demonstrates good practices in reducing its attack surface and overall code hygiene, but the raw SQL queries are a notable weakness that could be exploited.

Key Concerns

  • SQL queries not using prepared statements
  • No capability checks found
Vulnerabilities
None known

Cyr to Lat Reloaded – Transliteration of Links and File Names Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cyr to Lat Reloaded – Transliteration of Links and File Names Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
2 prepared
Unescaped Output
3
17 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

29% prepared7 total queries

Output Escaping

85% escaped20 total outputs
Attack Surface

Cyr to Lat Reloaded – Transliteration of Links and File Names Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
filterplugin_row_metacyr-and-lat.php:34
filtersanitize_titlecyr-and-lat.php:35
filtersanitize_file_namecyr-and-lat.php:36
filterinitcyr-and-lat.php:37
filterthemeisle_sdk_productscyr-and-lat.php:39
actionadmin_noticescyr-and-lat.php:74
actionwp_loadedincludes\admin-notices.php:139
actionadmin_footerincludes\admin-notices.php:159
actionadmin_noticesincludes\admin-notices.php:160
actionadmin_initincludes\plugins\acf.php:33
Maintenance & Trust

Cyr to Lat Reloaded – Transliteration of Links and File Names Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 13, 2026
PHP min version5.2
Downloads214K

Community Trust

Rating86/100
Number of ratings11
Active installs30K
Developer Profile

Cyr to Lat Reloaded – Transliteration of Links and File Names Developer Profile

Themeisle

37 plugins · 2.2M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
420 days
View full developer profile
Detection Fingerprints

How We Detect Cyr to Lat Reloaded – Transliteration of Links and File Names

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cyr-and-lat/assets/js/cyr-and-lat-acf.js
Script Paths
/wp-content/plugins/cyr-and-lat/assets/js/cyr-and-lat-acf.js

HTML / DOM Fingerprints

JS Globals
window.cyr_and_lat_dict
FAQ

Frequently Asked Questions about Cyr to Lat Reloaded – Transliteration of Links and File Names