
Cyrillic Permalinks Security & Risk Analysis
wordpress.org/plugins/cyrillic-slugsAutomatically transliterates Cyrillic letters in permalinks to their Latin phonetic equivalent. Multi-language. Can convert pre-existing permalinks.
Is Cyrillic Permalinks Safe to Use in 2026?
Generally Safe
Score 100/100Cyrillic Permalinks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cyrillic-slugs" plugin version 2.0.5 demonstrates a generally strong security posture based on the static analysis. The code adheres to good practices by exclusively using prepared statements for SQL queries, performing a high percentage of output escaping, and avoiding dangerous functions and file operations. The absence of known CVEs and any recorded vulnerabilities in its history further suggests a well-maintained and secure codebase.
However, a significant concern arises from the attack surface analysis. The plugin exposes three AJAX handlers, and critically, one of these lacks any authentication checks. This unprotected entry point could be a target for unauthenticated users to interact with the plugin's functionality, potentially leading to unintended consequences if the handler processes input without proper validation or authorization. While taint analysis shows no immediate critical or high severity issues, this single unprotected AJAX handler represents a concrete and actionable risk that needs addressing.
In conclusion, while the plugin exhibits many positive security attributes, the unprotected AJAX handler is a notable weakness. The lack of past vulnerabilities is encouraging, but it does not negate the current identified risk. Addressing the unprotected entry point should be the priority to fully secure the plugin.
Key Concerns
- Unprotected AJAX handler
Cyrillic Permalinks Security Vulnerabilities
Cyrillic Permalinks Code Analysis
Output Escaping
Cyrillic Permalinks Attack Surface
AJAX Handlers 3
WordPress Hooks 7
Maintenance & Trust
Cyrillic Permalinks Maintenance & Trust
Maintenance Signals
Community Trust
Cyrillic Permalinks Alternatives
Cyr to Lat Enhanced
cyr3lat
Converts Cyrillic, European and Georgian characters in post, term slugs and media file names into Latin characters.
Bulglish Permalinks
bulglish-permalinks
This plugin converts Bulgarian cyrillic characters in slugs and filenames to Latin characters, according to the official rules for transliteration.
Cyrillic 2 Latin
cyrillic2latin
This plugin convert WordPress from Cyrillic to Latin.
Cyr-To-Lat
cyr2lat
Convert Non-Latin characters in post, page and term slugs to Latin characters.
AutoConvert Greeklish Permalinks
autoconvert-greeklish-permalinks
Convert Greek characters to Latin on all your site's permalinks instantly.
Cyrillic Permalinks Developer Profile
2 plugins · 1K total installs
How We Detect Cyrillic Permalinks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cyrillic-slugs/css/cyrillic-slugs.css/wp-content/plugins/cyrillic-slugs/js/cyrillic-slugs.js/wp-content/plugins/cyrillic-slugs/js/cyrillic-slugs.jscyrillic-slugs/css/cyrillic-slugs.css?ver=cyrillic-slugs/js/cyrillic-slugs.js?ver=HTML / DOM Fingerprints
wpsf-settings--cyrillic-slugswpsf-settingswpsf-settings__headerwpsf-settings__content