GlotPress – Translation Propagation Security & Risk Analysis

wordpress.org/plugins/gp-translation-propagation

Brings Translation Propagation to GlotPress.

10 active installs v1.0.0 PHP + WP 4.4+ Updated Unknown
glotpresstranslation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GlotPress – Translation Propagation Safe to Use in 2026?

Generally Safe

Score 100/100

GlotPress – Translation Propagation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "gp-translation-propagation" v1.0.0 plugin exhibits an excellent security posture based on the provided static analysis. The complete absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and a lack of taint flows with unsanitized paths are all strong indicators of well-written and secure code. The plugin also adheres to best practices by not exposing any public-facing entry points through AJAX, REST API, or shortcodes without apparent authorization checks. The plugin's vulnerability history is also pristine, with no recorded CVEs, suggesting a history of security awareness and proactive maintenance or a very low-risk profile.

While the static analysis reveals a highly secure codebase, a notable point of concern arises from the complete absence of nonce and capability checks. Although the attack surface is currently zero, if any new functionality were to be introduced without implementing these crucial security measures, it could create significant vulnerabilities. This is the primary area of weakness in an otherwise robust security profile. Therefore, the plugin is secure for its current state but requires careful attention to authorization mechanisms should its functionality expand.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

GlotPress – Translation Propagation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GlotPress – Translation Propagation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries
Attack Surface

GlotPress – Translation Propagation Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actiongp_initgp-translation-propagation.php:32
actiongp_original_createdincludes\class-gp-translation-propagation.php:43
actiongp_translation_createdincludes\class-gp-translation-propagation.php:44
actiongp_translation_savedincludes\class-gp-translation-propagation.php:45
filtergp_enable_propagate_translations_across_projectsincludes\class-gp-translation-propagation.php:193
filtergp_enable_propagate_translations_across_projectsincludes\cli\import-originals.php:45
filtergp_enable_add_translations_from_other_projectsincludes\cli\import-originals.php:48
filtergp_enable_propagate_translations_across_projectsincludes\cli\translation-set.php:43
Maintenance & Trust

GlotPress – Translation Propagation Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedUnknown
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

GlotPress – Translation Propagation Developer Profile

Dominik Schilling

6 plugins · 106K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GlotPress – Translation Propagation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gp-translation-propagation/includes/class-gp-translation-propagation.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about GlotPress – Translation Propagation