Cyrillic To Latin Security & Risk Analysis

wordpress.org/plugins/cyrillic-to-latin

Cyrillic To Latin is a plugin for transforming Serbian Cyrillic .po files into Latin .po files.

20 active installs v1.0.1 PHP + WP 4.1+ Updated Aug 4, 2018
cyrilliclanguagelatinserbiantranslate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Cyrillic To Latin Safe to Use in 2026?

Generally Safe

Score 85/100

Cyrillic To Latin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "cyrillic-to-latin" plugin, version 1.0.1, exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL injection by utilizing prepared statements exclusively and has no recorded vulnerability history, suggesting a generally well-maintained codebase. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. However, a critical concern arises from the taint analysis, which reveals one flow with unsanitized paths. Furthermore, the static analysis indicates that 100% of the nine output operations are not properly escaped, posing a significant Cross-Site Scripting (XSS) risk. The presence of file operations without clear context on their purpose or security controls also warrants caution. While the plugin is free from known CVEs and has a clean history, the identified taint flow and unescaped output are serious weaknesses that require immediate attention to prevent potential exploitation.

Key Concerns

  • Unsanitized path in taint flow
  • All outputs are unescaped
  • File operations present
Vulnerabilities
None known

Cyrillic To Latin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Cyrillic To Latin Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Cyrillic To Latin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
9
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped9 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<start> (src\Resources\Views\start.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Cyrillic To Latin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionplugins_loadedcyrillic-to-latin.php:21
actionadmin_menucyrillic-to-latin.php:38
Maintenance & Trust

Cyrillic To Latin Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedAug 4, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Cyrillic To Latin Developer Profile

dlesendric

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cyrillic To Latin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrap
HTML Comments
container
FAQ

Frequently Asked Questions about Cyrillic To Latin