Elia for WPML Security & Risk Analysis

wordpress.org/plugins/elia-for-wpml

A plugin to activate Elia Elhuyar's machine translator in WPML. Requires WPML plugin.

20 active installs v1.2 PHP + WP 3.6+ Updated May 9, 2025
eliamultilingualtranslationwpml
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Elia for WPML Safe to Use in 2026?

Generally Safe

Score 92/100

Elia for WPML has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'elia-for-wpml' v1.2 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of identified dangerous functions, raw SQL queries, and taint flows with unsanitized paths suggests a diligent approach to secure coding practices. Furthermore, the lack of any recorded vulnerabilities, critical or otherwise, indicates a stable and potentially well-maintained codebase.

However, there are areas that warrant attention. The significant percentage of improperly escaped output (37%) presents a potential risk for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. Additionally, the complete absence of nonce checks and capability checks across all entry points, while currently mitigated by a zero attack surface, leaves the plugin vulnerable should new entry points be introduced without proper authorization mechanisms. The file operations and external HTTP requests, while not flagged as inherently risky, are points of interest that would require further manual review to confirm their security implications.

In conclusion, 'elia-for-wpml' v1.2 demonstrates good foundational security with no historical vulnerabilities and a clean record for critical code constructs. The primary concerns revolve around the unescaped output and the lack of explicit authorization checks on potential entry points. These weaknesses, though not currently exploited according to the data, represent an opportunity for attackers if the attack surface expands or if user-controlled input finds its way into unescaped output contexts.

Key Concerns

  • Improper output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Elia for WPML Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Elia for WPML Release Timeline

v1.2.1
v1.2Current
Code Analysis
Analyzed Mar 16, 2026

Elia for WPML Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
2
Bundled Libraries
0

Output Escaping

63% escaped16 total outputs
Attack Surface

Elia for WPML Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_noticeselia_wpml.php:22
actionwp_enqueue_scriptsincludes\elia_wpml-includes.php:8
actionadmin_menuincludes\elia_wpml-options.php:3
actionadmin_noticestrunk\elia_wpml.php:22
actionwp_enqueue_scriptstrunk\includes\elia_wpml-includes.php:8
actionadmin_menutrunk\includes\elia_wpml-options.php:3
Maintenance & Trust

Elia for WPML Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMay 9, 2025
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Elia for WPML Developer Profile

Elhuyar

1 plugin · 20 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Elia for WPML

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elia-for-wpml/includes/css/elia_wpml.css

HTML / DOM Fingerprints

CSS Classes
elia_wpml-admin-css
HTML Comments
WPML is active, proceed with WPML-specific logic.So anyone who registers a .eus domain and uses the WordPress platform can translate their website content with theRegister your .eus web to start using the Elia with WPML.You will need an API Key and API id to use the service.+4 more
Data Attributes
name="ELIA_settings[api_id]"name="ELIA_settings[api_key]"name="ELIA_settings[bg_color]"
JS Globals
jQuery
Shortcode Output
Zorionak! Elia Wordpress plugina instalatuta duzu. Zure webgunearen edukia itzultzen hasteko, osatu azpiko eremuak.GOGORATU ELIA ERABILTZEKO EZINBESTEKOA DELA WPML INSTALATUTA ETA AKTIBATUTA IZATEA(https://wpml.org/)LAGUNTZA BEHAR DUZU?
FAQ

Frequently Asked Questions about Elia for WPML