Prisna GWT – Google Website Translator Security & Risk Analysis

wordpress.org/plugins/google-website-translator

Easily translate your WordPress site into 100+ languages to make it multilingual. A simple and complete multilingual solution for WordPress.

8K active installs v1.4.15 PHP 5.6+ WP 3.3+ Updated Dec 8, 2025
google-translatemultilingualtranslatetranslate-wordpresstranslation
95
A · Safe
CVEs total3
Unpatched0
Last CVEMar 3, 2025
Safety Verdict

Is Prisna GWT – Google Website Translator Safe to Use in 2026?

Generally Safe

Score 95/100

Prisna GWT – Google Website Translator has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Mar 3, 2025Updated 3mo ago
Risk Assessment

The 'google-website-translator' plugin, version 1.4.15, presents a mixed security posture. While it demonstrates strengths in handling SQL queries with prepared statements and includes some nonce and capability checks, significant concerns arise from its vulnerability history and static analysis findings. The plugin has a history of three known CVEs, including a past critical vulnerability, indicating a pattern of exploitable flaws. The presence of the 'unserialize' function is a red flag, especially when coupled with the taint analysis showing flows with unsanitized paths. Although no critical or high severity taint flows were identified in this specific static analysis, the existence of unsanitized paths combined with the `unserialize` function creates a potential avenue for deserialization vulnerabilities. Furthermore, the low percentage of properly escaped output suggests a risk of cross-site scripting (XSS) vulnerabilities, which aligns with past reported vulnerability types. The plugin's limited attack surface in terms of entry points is a positive sign, but the identified code signals and historical data point to latent risks that require attention.

Key Concerns

  • Vulnerability history: 1 critical CVE
  • Vulnerability history: 2 medium CVEs
  • Dangerous function: unserialize
  • Taint analysis: flows with unsanitized paths
  • Output escaping: 17% properly escaped
  • Nonce checks: 1 total
Vulnerabilities
3

Prisna GWT – Google Website Translator Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Critical
1
Medium
2

3 total CVEs

CVE-2024-12680medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Prisna GWT – Google Website Translator <= 1.4.13 - Authenticated (Admin+) Stored Cross-Site Scripting

Mar 3, 2025 Patched in 1.4.14 (82d)
CVE-2024-12679medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Prisna GWT – Google Website Translator <= 1.4.13 - Authenticated (Admin+) Stored Cross-Site Scripting

Mar 3, 2025 Patched in 1.4.14 (82d)
CVE-2024-8514critical · 9.1Deserialization of Untrusted Data

Prisna GWT - Google Website Translator <= 1.4.11 - Authenticated (Admin+) PHP Object Injection

Sep 24, 2024 Patched in 1.4.12 (1d)
Code Analysis
Analyzed Mar 16, 2026

Prisna GWT – Google Website Translator Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
3 prepared
Unescaped Output
10
2 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$unserialize = @unserialize($to_unserialize, array('allowed_classes' => false));classes\admin.class.php:286

SQL Query Safety

100% prepared3 total queries

Output Escaping

17% escaped12 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
renderCSS (classes\common.class.php:35)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Prisna GWT – Google Website Translator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initclasses\admin.class.php:10
actionadmin_headclasses\admin.class.php:11
actionplugins_loadedclasses\admin.class.php:12
actionadmin_menuclasses\admin.class.php:83
actionwidgets_initclasses\common.class.php:999
actionwp_footerclasses\main.class.php:8
Maintenance & Trust

Prisna GWT – Google Website Translator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 8, 2025
PHP min version5.6
Downloads345K

Community Trust

Rating90/100
Number of ratings54
Active installs8K
Developer Profile

Prisna GWT – Google Website Translator Developer Profile

Prisna

4 plugins · 8K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
47 days
View full developer profile
Detection Fingerprints

How We Detect Prisna GWT – Google Website Translator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/google-website-translator/javascript/common.class.js/wp-content/plugins/google-website-translator/javascript/admin.class.js/wp-content/plugins/google-website-translator/styles/admin.css
Script Paths
/javascript/common.class.js/javascript/admin.class.js
Version Parameters
google-website-translator/javascript/common.class.js?ver=google-website-translator/javascript/admin.class.js?ver=google-website-translator/styles/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
prisna-gwt-admin
Data Attributes
data-prisna-gwt-tab
JS Globals
prisna_gwt_admin_common
FAQ

Frequently Asked Questions about Prisna GWT – Google Website Translator