
GP Import Translations from wordress.org Security & Risk Analysis
wordpress.org/plugins/gp-import-from-wp-orgA plugin for GlotPress as a WordPress plugin that imports a language from wordpress.org's translation site.
Is GP Import Translations from wordress.org Safe to Use in 2026?
Generally Safe
Score 100/100GP Import Translations from wordress.org has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gp-import-from-wp-org" plugin, version 0.5, exhibits a generally good security posture based on the provided static analysis. The plugin has a commendably small attack surface with zero identified entry points, and importantly, zero unprotected entry points. The absence of dangerous functions and the use of prepared statements for all SQL queries are significant strengths. Furthermore, the plugin demonstrates a clean vulnerability history with no recorded CVEs.
However, there are a few areas for concern. The critical signal is that 100% of output is not properly escaped. This means that any dynamic data outputted by the plugin could potentially be vulnerable to Cross-Site Scripting (XSS) attacks if that data is not already sufficiently sanitized before being passed to the output functions. While the plugin has a capability check, it has zero nonce checks, which is a weakness for certain types of operations that might be performed through its limited functionality, especially if any of the file operations involve user-supplied input.
In conclusion, the plugin's minimal attack surface and lack of historical vulnerabilities are positive indicators. The primary concern lies in the unescaped output, which represents a clear XSS risk. The lack of nonce checks also presents a potential, albeit less defined, risk depending on the nature of the file operations. Addressing the output escaping and implementing nonce checks would significantly improve the plugin's overall security.
Key Concerns
- Output escaping missing
- Nonce checks missing
GP Import Translations from wordress.org Security Vulnerabilities
GP Import Translations from wordress.org Code Analysis
Output Escaping
GP Import Translations from wordress.org Attack Surface
WordPress Hooks 2
Maintenance & Trust
GP Import Translations from wordress.org Maintenance & Trust
Maintenance Signals
Community Trust
GP Import Translations from wordress.org Alternatives
Localize WordPress
localize
Easily switch to any localization from GlotPress
WP Translation Status
wp-translation
Make a link to GlotPress centralised translation so contributor can help translating the plugin that do not have yet a translation in the local site l …
GP Remove Powered By
gp-removed-powered-by
A plugin for GlotPress as a WordPress plugin that removes the "Powered By" in the footer.
GP Additional Links
gp-additional-links
A plugin for GlotPress as a WordPress plugin that adds a link to the WordPress dashboard for admins in the GlotPress page as well as a link to the Glo …
GP Download Name
gp-download-name
A plugin for GlotPress that uses a customizable template for the download file name.
GP Import Translations from wordress.org Developer Profile
34 plugins · 8K total installs
How We Detect GP Import Translations from wordress.org
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
Import from wordpress.org: [Stable] [Development]