
Translate WordPress – Google Language Translator Security & Risk Analysis
wordpress.org/plugins/google-language-translatorTranslate WordPress with Google Language Translator multilanguage plugin which allows to insert Google Translate widget anywhere on your website.
Is Translate WordPress – Google Language Translator Safe to Use in 2026?
Generally Safe
Score 97/100Translate WordPress – Google Language Translator has a strong security track record. Known vulnerabilities have been patched promptly.
The "google-language-translator" plugin version 6.0.20 exhibits a mixed security posture. While it demonstrates good practices in terms of SQL query sanitization and has no currently unpatched CVEs, several areas raise concerns. The static analysis reveals a notable percentage of improperly escaped output (42%), which presents a potential risk for cross-site scripting (XSS) vulnerabilities, especially given the plugin's vulnerability history which includes "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')". The taint analysis also identified flows with unsanitized paths, although none reached a critical or high severity in this scan, they still indicate areas where input handling might not be robust enough.
The vulnerability history is a significant concern, with 8 known CVEs in total, including 2 high-severity ones. The common vulnerability types highlight a recurring pattern of "Missing Authorization" and "Cross-site Scripting", suggesting that these types of weaknesses have been present in the plugin's past development. While there are currently no unpatched vulnerabilities, this history indicates a need for continued vigilance and potential for new vulnerabilities to emerge. The plugin's strengths lie in its secure SQL handling and lack of unpatched critical issues, but the unescaped output and historical vulnerability trends necessitate caution.
Key Concerns
- Significant portion of output not properly escaped
- History of high severity CVEs
- History of XSS vulnerabilities
- History of Missing Authorization vulnerabilities
- Flows with unsanitized paths identified
Translate WordPress – Google Language Translator Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
Google Language Translator <= 6.0.19 - Missing Authorization via admin notifications
Google Language Translator < 6.0.20 - Missing Authorization to Notice Dismissal
Translate WordPress with GTranslate <= 2.9.8 & Translate WordPress – Google Language Translator <= 6.0.13 - Missing Authorization to Sensitive Information Disclosure
Translate WordPress - Google Language Translator <= 6.0.11 - Admin+ Stored Cross-Site Scripting
Google Language Translator <= 6.0.9 - Reflected Cross-Site Scripting
Google Language Translator <= 6.0.9 - Authenticated Cross-Site Scripting
Google Language Translator <= 5.0.05 - Cross-Site Scripting
Google Language Translator <= 4.0.9 - Authenticated Stored Cross-Site Scripting
Translate WordPress – Google Language Translator Code Analysis
Output Escaping
Data Flow Analysis
Translate WordPress – Google Language Translator Attack Surface
Shortcodes 2
WordPress Hooks 28
Maintenance & Trust
Translate WordPress – Google Language Translator Maintenance & Trust
Maintenance Signals
Community Trust
Translate WordPress – Google Language Translator Alternatives
Multilanguage by BestWebSoft – WordPress Translation Plugin and Language Switcher
multilanguage
The ultimate WordPress translation solution with built-in language translator. Create multilingual content, switch languages, and translate your entir …
Translate WordPress with GTranslate
gtranslate
Translate WordPress with Google Translate multilanguage plugin to make your website multilingual. Complete multilingual SEO solution for WordPress.
WPML Shortcodes
wpml-shortcodes
Adds shortcodes to the WPML environment, like wpml__, wpml_e and more. Makes WP full WPML ready.
WPML Translate Shortcode
wpml-translate-shortcode
Adds the wpml_translate shortcode to your shortcode suite. You can also use the wpml_text_if_language( $lang, $content ) in your php code.
Translate WordPress with Google Languages Translator
translate-wp-with-google-languages-translator
Simple and powerful Google Translator plugin. Use it with a shortcode or with a widget, and make your website multilingual and accessible to everybody …
Translate WordPress – Google Language Translator Developer Profile
4 plugins · 1.0M total installs
How We Detect Translate WordPress – Google Language Translator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/google-language-translator/css/style.css/wp-content/plugins/google-language-translator/css/flags.css/wp-content/plugins/google-language-translator/js/main.js/wp-content/plugins/google-language-translator/js/main.jsgoogle-language-translator/css/style.css?ver=google-language-translator/css/flags.css?ver=google-language-translator/js/main.js?ver=HTML / DOM Fingerprints
gtranslate_wrappergtranslate_selectorgtranslate_flagsgtranslate_verticalgtranslate_horizontalgtranslate_popupgtranslate_menugtranslate_widget+3 moredata-gt-translate-innergoogleTranslateElementInit[google-translator][glt]