
Cyr to Lat Reloaded – Transliteration of Links and File Names Security & Risk Analysis
wordpress.org/plugins/cyr-and-latConverts Cyrillic, Georgian, and Greek URLs and file names into readable Latin characters.
Is Cyr to Lat Reloaded – Transliteration of Links and File Names Safe to Use in 2026?
Generally Safe
Score 100/100Cyr to Lat Reloaded – Transliteration of Links and File Names has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'cyr-and-lat' v1.3.1 plugin exhibits a strong security posture based on the provided static analysis. It boasts a zero attack surface for both AJAX and REST API interactions, and lacks shortcodes or cron events, significantly minimizing potential entry points. The code analysis reveals responsible use of dangerous functions and file operations, with a commendable 85% of output properly escaped. The presence of nonce checks is also a positive indicator of security awareness.
However, there are areas for improvement. A concerning 71% of SQL queries are not using prepared statements, which presents a moderate risk of SQL injection vulnerabilities if these queries handle user-supplied data without proper sanitization. The absence of capability checks on any part of the code, combined with the use of raw SQL queries, raises concerns about privilege escalation or unauthorized data access if any part of the plugin's logic were to be triggered in an unexpected way or if user input were to influence the SQL execution.
The plugin's vulnerability history is clean, with zero known CVEs. This, coupled with the clean taint analysis, suggests that historically, the plugin has not been a source of exploitable vulnerabilities. While the lack of past issues is reassuring, it does not negate the risks identified in the current static analysis, particularly concerning the SQL query handling. The plugin demonstrates good practices in reducing its attack surface and overall code hygiene, but the raw SQL queries are a notable weakness that could be exploited.
Key Concerns
- SQL queries not using prepared statements
- No capability checks found
Cyr to Lat Reloaded – Transliteration of Links and File Names Security Vulnerabilities
Cyr to Lat Reloaded – Transliteration of Links and File Names Code Analysis
SQL Query Safety
Output Escaping
Cyr to Lat Reloaded – Transliteration of Links and File Names Attack Surface
WordPress Hooks 10
Maintenance & Trust
Cyr to Lat Reloaded – Transliteration of Links and File Names Maintenance & Trust
Maintenance Signals
Community Trust
Cyr to Lat Reloaded – Transliteration of Links and File Names Alternatives
Cyrlitera – Transliteration of Links and File Names
cyrlitera
Convert Cyrillic and Georgian URLs and file names to Latin. Works for all post types, pages, and terms. Custom characters, URL redirects & more.
Cyr-To-Lat
cyr2lat
Convert Non-Latin characters in post, page and term slugs to Latin characters.
Cyr to Lat Enhanced
cyr3lat
Converts Cyrillic, European and Georgian characters in post, term slugs and media file names into Latin characters.
Bulglish Permalinks
bulglish-permalinks
This plugin converts Bulgarian cyrillic characters in slugs and filenames to Latin characters, according to the official rules for transliteration.
Transliterator – Multilingual and Multi-script Text Conversion
serbian-transliteration
Universal transliteration for permalinks, posts, tags, categories, media, files, search and more, rendering them universally readable.
Cyr to Lat Reloaded – Transliteration of Links and File Names Developer Profile
37 plugins · 2.2M total installs
How We Detect Cyr to Lat Reloaded – Transliteration of Links and File Names
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cyr-and-lat/assets/js/cyr-and-lat-acf.js/wp-content/plugins/cyr-and-lat/assets/js/cyr-and-lat-acf.jsHTML / DOM Fingerprints
window.cyr_and_lat_dict