Cyrillic Permalinks Security & Risk Analysis

wordpress.org/plugins/cyrillic-slugs

Automatically transliterates Cyrillic letters in permalinks to their Latin phonetic equivalent. Multi-language. Can convert pre-existing permalinks.

300 active installs v2.0.5 PHP 5.6+ WP 2.0.2+ Updated Jun 26, 2025
bulgariancyrillicpermalinksrussianslugs
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cyrillic Permalinks Safe to Use in 2026?

Generally Safe

Score 100/100

Cyrillic Permalinks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "cyrillic-slugs" plugin version 2.0.5 demonstrates a generally strong security posture based on the static analysis. The code adheres to good practices by exclusively using prepared statements for SQL queries, performing a high percentage of output escaping, and avoiding dangerous functions and file operations. The absence of known CVEs and any recorded vulnerabilities in its history further suggests a well-maintained and secure codebase.

However, a significant concern arises from the attack surface analysis. The plugin exposes three AJAX handlers, and critically, one of these lacks any authentication checks. This unprotected entry point could be a target for unauthenticated users to interact with the plugin's functionality, potentially leading to unintended consequences if the handler processes input without proper validation or authorization. While taint analysis shows no immediate critical or high severity issues, this single unprotected AJAX handler represents a concrete and actionable risk that needs addressing.

In conclusion, while the plugin exhibits many positive security attributes, the unprotected AJAX handler is a notable weakness. The lack of past vulnerabilities is encouraging, but it does not negate the current identified risk. Addressing the unprotected entry point should be the priority to fully secure the plugin.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

Cyrillic Permalinks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cyrillic Permalinks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
194 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped211 total outputs
Attack Surface
1 unprotected

Cyrillic Permalinks Attack Surface

Entry Points3
Unprotected1

AJAX Handlers 3

authwp_ajax_cyr_slugs_update_existingclass-cyrslugs.php:55
authwp_ajax_wpsf_export_settingswp-settings-framework\class-wordpresssettingsframework.php:135
authwp_ajax_wpsf_import_settingswp-settings-framework\class-wordpresssettingsframework.php:136
WordPress Hooks 7
actionadmin_menuclass-cyrslugs.php:50
actionwpsf_after_settings_cyr_slugs_settings_generalclass-cyrslugs.php:51
filterwp_insert_post_dataclass-cyrslugs.php:64
filterwpsf_register_settings_cyr_slugs_settings_generalsettings\settings-general.php:2
actionadmin_initwp-settings-framework\class-wordpresssettingsframework.php:118
actionadmin_noticeswp-settings-framework\class-wordpresssettingsframework.php:123
actionadmin_enqueue_scriptswp-settings-framework\class-wordpresssettingsframework.php:125
Maintenance & Trust

Cyrillic Permalinks Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 26, 2025
PHP min version5.6
Downloads16K

Community Trust

Rating74/100
Number of ratings3
Active installs300
Developer Profile

Cyrillic Permalinks Developer Profile

pbosakov

2 plugins · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cyrillic Permalinks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cyrillic-slugs/css/cyrillic-slugs.css/wp-content/plugins/cyrillic-slugs/js/cyrillic-slugs.js
Script Paths
/wp-content/plugins/cyrillic-slugs/js/cyrillic-slugs.js
Version Parameters
cyrillic-slugs/css/cyrillic-slugs.css?ver=cyrillic-slugs/js/cyrillic-slugs.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpsf-settings--cyrillic-slugswpsf-settingswpsf-settings__headerwpsf-settings__content
FAQ

Frequently Asked Questions about Cyrillic Permalinks