Dilbaz Localization Tool Security & Risk Analysis

wordpress.org/plugins/dilbaz-localization-tool

Scan plugins and themes to extract translatable strings and generate POT files directly from the WordPress admin panel.

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Mar 23, 2026
gettexti18nlocalizationpot-generatortranslation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dilbaz Localization Tool Safe to Use in 2026?

Generally Safe

Score 100/100

Dilbaz Localization Tool has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'dilbaz-localization-tool' v1.0.0 exhibits a generally good security posture with several positive indicators. The code demonstrates a strong adherence to secure coding practices, particularly with 100% of SQL queries using prepared statements and 99% of outputs being properly escaped. The absence of known CVEs and a history free of vulnerabilities further bolsters confidence in its security. However, a significant concern arises from the presence of two AJAX handlers that lack authentication checks. This creates a direct attack vector that could be exploited by unauthenticated users to trigger potentially sensitive actions within the plugin.

Key Concerns

  • AJAX handlers without authentication checks
Vulnerabilities
None known

Dilbaz Localization Tool Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Dilbaz Localization Tool Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Dilbaz Localization Tool Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
191 escaped
Nonce Checks
1
Capability Checks
5
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped192 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
ajax_download_pot (includes/class-admin.php:673)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Dilbaz Localization Tool Attack Surface

Entry Points6
Unprotected2

AJAX Handlers 6

authwp_ajax_dilbaz_ltlt_prepare_filesincludes/class-admin.php:50
authwp_ajax_dilbaz_ltlt_run_scanincludes/class-admin.php:51
authwp_ajax_dilbaz_ltlt_get_stringsincludes/class-admin.php:52
authwp_ajax_dilbaz_ltlt_generate_potincludes/class-admin.php:53
authwp_ajax_dilbaz_ltlt_download_potincludes/class-admin.php:54
authwp_ajax_dilbaz_ltlt_generate_poincludes/class-admin.php:55
WordPress Hooks 3
actionadmin_menuincludes/class-admin.php:48
actionadmin_enqueue_scriptsincludes/class-admin.php:49
filteradmin_titleincludes/class-admin.php:56
Maintenance & Trust

Dilbaz Localization Tool Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 23, 2026
PHP min version7.4
Downloads78

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Dilbaz Localization Tool Developer Profile

Atakan Au

12 plugins · 2K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
27 days
View full developer profile
Detection Fingerprints

How We Detect Dilbaz Localization Tool

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dilbaz-localization-tool/assets/js/admin.js/wp-content/plugins/dilbaz-localization-tool/assets/css/admin.css
Script Paths
/wp-content/plugins/dilbaz-localization-tool/assets/js/admin.js
Version Parameters
dilbaz-localization-tool/assets/js/admin.js?ver=dilbaz-localization-tool/assets/css/admin.css?ver=

HTML / DOM Fingerprints

Data Attributes
dilbaz_ltlt_nonce
JS Globals
dilbazInitial
REST Endpoints
/wp-json/dilbaz-ltlt/v1/prepare-files/wp-json/dilbaz-ltlt/v1/run-scan/wp-json/dilbaz-ltlt/v1/get-strings/wp-json/dilbaz-ltlt/v1/generate-pot/wp-json/dilbaz-ltlt/v1/download-pot/wp-json/dilbaz-ltlt/v1/generate-po
FAQ

Frequently Asked Questions about Dilbaz Localization Tool