
GP Bulk Download Translations Security & Risk Analysis
wordpress.org/plugins/gp-bulk-download-translationsA plugin for GlotPress as a WordPress plugin that downloads all translation sets for a project as a single zip file.
Is GP Bulk Download Translations Safe to Use in 2026?
Generally Safe
Score 92/100GP Bulk Download Translations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'gp-bulk-download-translations' plugin v1.2 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals indicate good development practices, with no dangerous functions identified, all SQL queries using prepared statements, and all output properly escaped. The plugin also avoids external HTTP requests, which is a positive security measure.
However, there are notable areas of concern. The complete lack of nonce checks and capability checks across all identified entry points is a significant weakness. While the attack surface is currently zero, any future addition of functionality without implementing these fundamental security mechanisms would create a direct vulnerability. The 8 file operations, while not inherently malicious, warrant attention as they represent potential avenues for exploitation if not handled with extreme care and proper sanitization, especially in the absence of explicit security checks.
The plugin's vulnerability history is remarkably clean, with no recorded CVEs. This suggests either a history of secure development or a lack of significant public scrutiny. Nevertheless, the absence of security mechanisms like nonces and capability checks in the current codebase represents a proactive security risk that should be addressed.
Key Concerns
- No nonce checks
- No capability checks
- File operations without apparent checks
GP Bulk Download Translations Security Vulnerabilities
GP Bulk Download Translations Code Analysis
GP Bulk Download Translations Attack Surface
WordPress Hooks 2
Maintenance & Trust
GP Bulk Download Translations Maintenance & Trust
Maintenance Signals
Community Trust
GP Bulk Download Translations Alternatives
Localize WordPress
localize
Easily switch to any localization from GlotPress
WP Translation Status
wp-translation
Make a link to GlotPress centralised translation so contributor can help translating the plugin that do not have yet a translation in the local site l …
GP Remove Powered By
gp-removed-powered-by
A plugin for GlotPress as a WordPress plugin that removes the "Powered By" in the footer.
GP Additional Links
gp-additional-links
A plugin for GlotPress as a WordPress plugin that adds a link to the WordPress dashboard for admins in the GlotPress page as well as a link to the Glo …
GP Download Name
gp-download-name
A plugin for GlotPress that uses a customizable template for the download file name.
GP Bulk Download Translations Developer Profile
34 plugins · 8K total installs
How We Detect GP Bulk Download Translations
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gp-bulk-download-translations/css/style.css/wp-content/plugins/gp-bulk-download-translations/js/scripts.js/wp-content/plugins/gp-bulk-download-translations/js/scripts.jsgp-bulk-download-translations/css/style.css?ver=gp-bulk-download-translations/js/scripts.js?ver=HTML / DOM Fingerprints
Bulk Export Translations