
GP Use Slug for Downloads Security & Risk Analysis
wordpress.org/plugins/gp-use-slug-for-downloadsA plugin for GlotPress as a WordPress plugin that uses the translation set slug for the name of the download file name.
Is GP Use Slug for Downloads Safe to Use in 2026?
Generally Safe
Score 85/100GP Use Slug for Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gp-use-slug-for-downloads" v1.0 plugin exhibits a remarkably clean static analysis report, indicating adherence to several core security best practices. The absence of known dangerous functions, direct SQL queries, unescaped output, file operations, and external HTTP requests is highly positive. Furthermore, the lack of identified taint flows suggests that data input is likely being handled safely within the analyzed code.
However, the analysis also reveals a concerning lack of explicit security mechanisms. The complete absence of AJAX handlers, REST API routes, shortcodes, cron events, nonce checks, and capability checks is a significant weakness. While the current version may not expose these entry points, it implies that the plugin has no built-in protection for potential future additions or if its intended functionality is extended. The vulnerability history is also empty, which is good, but it doesn't mitigate the risks associated with missing fundamental security controls.
In conclusion, while the plugin's current code is free from common vulnerabilities like SQL injection or XSS due to its limited functionality and careful implementation, its overall security posture is compromised by the complete absence of protective measures. This leaves it vulnerable to potential future attacks if functionality is added without corresponding security hardening, or if external factors exploit an unaddressed aspect of its operation.
Key Concerns
- No capability checks
- No nonce checks
- No AJAX handlers with auth checks
- No REST API routes with permission callbacks
- No shortcodes
- No cron events
GP Use Slug for Downloads Security Vulnerabilities
GP Use Slug for Downloads Code Analysis
GP Use Slug for Downloads Attack Surface
WordPress Hooks 2
Maintenance & Trust
GP Use Slug for Downloads Maintenance & Trust
Maintenance Signals
Community Trust
GP Use Slug for Downloads Alternatives
Localize WordPress
localize
Easily switch to any localization from GlotPress
WP Translation Status
wp-translation
Make a link to GlotPress centralised translation so contributor can help translating the plugin that do not have yet a translation in the local site l …
GP Remove Powered By
gp-removed-powered-by
A plugin for GlotPress as a WordPress plugin that removes the "Powered By" in the footer.
GP Additional Links
gp-additional-links
A plugin for GlotPress as a WordPress plugin that adds a link to the WordPress dashboard for admins in the GlotPress page as well as a link to the Glo …
GP Download Name
gp-download-name
A plugin for GlotPress that uses a customizable template for the download file name.
GP Use Slug for Downloads Developer Profile
34 plugins · 8K total installs
How We Detect GP Use Slug for Downloads
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.