
Translate WordPress with GTranslate Security & Risk Analysis
wordpress.org/plugins/gtranslateTranslate WordPress with Google Translate multilanguage plugin to make your website multilingual. Complete multilingual SEO solution for WordPress.
Is Translate WordPress with GTranslate Safe to Use in 2026?
Generally Safe
Score 99/100Translate WordPress with GTranslate has a strong security track record. Known vulnerabilities have been patched promptly.
The gTranslate v3.0.9 plugin presents a mixed security picture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and performing a nonce check. However, there are notable concerns. The taint analysis reveals flows with unsanitized paths, indicating potential for attackers to inject malicious input, although no critical or high severity issues were found in this specific analysis. The output escaping is also a concern, with a significant portion (38%) of outputs not being properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities. The plugin's history of 5 medium severity CVEs, primarily related to XSS and Open Redirect, and its most recent vulnerability in August 2023, suggest a pattern of past security weaknesses that require ongoing vigilance. While the current version appears to have no unpatched critical or high vulnerabilities, the historical trend and the identified output escaping issues warrant careful attention.
Key Concerns
- Significant portion of outputs not properly escaped
- Flows with unsanitized paths found in taint analysis
- History of medium severity CVEs (XSS, Open Redirect)
Translate WordPress with GTranslate Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
GTranslate <= 3.0.3 - Authenticated (Administrator+) Cross-Site Scripting via Multiple Parameters
Translate WordPress with GTranslate <= 2.9.6 - Reflected Cross-Site Scripting
GTranslate Pro and GTranslate Enterprise <= 2.8.64 - Reflected Cross-Site Scripting
GTranslate <= 2.8.51 - Reflected Cross Site Scripting
Translate WordPress with GTranslate <= 2.8.10 - Open Redirect
Translate WordPress with GTranslate Code Analysis
Output Escaping
Data Flow Analysis
Translate WordPress with GTranslate Attack Surface
Shortcodes 3
WordPress Hooks 34
Maintenance & Trust
Translate WordPress with GTranslate Maintenance & Trust
Maintenance Signals
Community Trust
Translate WordPress with GTranslate Alternatives
DevBrothers Simple Translator
devbrothers-simple-translator
Simple and free language switcher based on Google Translate. Shortcodes, widgets, customizable styles.
Polylang
polylang
Go multilingual in a simple and efficient way. Keep writing posts and taxonomy terms as usual while defining their languages all at once.
Translate WordPress – Google Language Translator
google-language-translator
Translate WordPress with Google Language Translator multilanguage plugin which allows to insert Google Translate widget anywhere on your website.
WP Multilang – Translation and Multilingual Plugin
wp-multilang
Multilingual plugin for WordPress. Go Multilingual in minutes with full WordPress support. Translate your site easily with this localization plugin.
Multilanguage by BestWebSoft – WordPress Translation Plugin and Language Switcher
multilanguage
The ultimate WordPress translation solution with built-in language translator. Create multilingual content, switch languages, and translate your entir …
Translate WordPress with GTranslate Developer Profile
4 plugins · 1.0M total installs
How We Detect Translate WordPress with GTranslate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gtranslate/gtranslate-widget.css/wp-content/plugins/gtranslate/gtranslate-widget.js/wp-content/plugins/gtranslate/gtranslate-main.js/wp-content/plugins/gtranslate/gtranslate-admin.js/wp-content/plugins/gtranslate/gtranslate-widget.css/wp-content/plugins/gtranslate/gtranslate-widget.js/wp-content/plugins/gtranslate/gtranslate-widget.js/wp-content/plugins/gtranslate/gtranslate-main.js/wp-content/plugins/gtranslate/gtranslate-admin.jsgtranslate/style.css?ver=gtranslate/script.js?ver=HTML / DOM Fingerprints
gtranslate_wrappergtranslate_flagsgtranslate_maingtranslate_widgetGTranslateGTranslate widgetdata-gt-href-langgtranslategtranslate_params/wp-json/gtranslate/v1/translate[GTranslate][gtranslate][gt-link]