CSV Format for GlotPress Security & Risk Analysis

wordpress.org/plugins/gp-format-csv

Adds the CSV format to GlotPress to export/import translations and originals.

0 active installs v1.0.3 PHP 7.4+ WP 5.1+ Updated Apr 18, 2025
csvglotpressi18nl10nwordpress
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CSV Format for GlotPress Safe to Use in 2026?

Generally Safe

Score 100/100

CSV Format for GlotPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "gp-format-csv" plugin v1.0.3 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events, coupled with zero total entry points, significantly minimizes the potential attack surface. Furthermore, the code demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage of output being properly escaped. The presence of a capability check and only one file operation are also positive indicators.

The lack of any taint analysis findings, including unsanitized paths or critical/high severity flows, is a significant strength. This suggests that data flowing through the plugin is handled securely, reducing the risk of common injection vulnerabilities. The plugin also has no recorded vulnerability history, indicating a history of secure development and maintenance. The overall picture is one of a well-secured plugin with minimal apparent risks.

While the plugin is generally robust, the primary area for potential, albeit low, concern is the one file operation that doesn't have an explicit capability check noted in the 'CODE SIGNALS'. Without further context on this file operation, it's difficult to assess its risk. However, given the other strong security signals, this is likely a minor oversight rather than a significant vulnerability. The absence of nonce checks is also noted, but with no identified entry points requiring them, this is not a current concern.

Key Concerns

  • One file operation without capability check
  • No nonce checks on entry points
Vulnerabilities
None known

CSV Format for GlotPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CSV Format for GlotPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
5 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped6 total outputs
Attack Surface

CSV Format for GlotPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initgp-format-csv.php:65
actionadmin_noticesgp-format-csv.php:94
actiongp_initgp-format-csv.php:182
Maintenance & Trust

CSV Format for GlotPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedApr 18, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

CSV Format for GlotPress Developer Profile

Pedro Mendonça

7 plugins · 120 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CSV Format for GlotPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gp-format-csv/
Version Parameters
gp-format-csv.php?ver=gp-format-csv/assets/css/style.css?ver=gp-format-csv/assets/js/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about CSV Format for GlotPress