HHG for TranslatePress Security & Risk Analysis

wordpress.org/plugins/hhg-for-translatepress

Add AI translation engines (Gemini, Hunyuan, OpenAI, GLM) to TranslatePress with multi-model support and beautiful interface.

400 active installs v1.0.4 PHP 7.4+ WP 5.6+ Updated Dec 12, 2025
geminimultilingualopenaitranslatepresstranslation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HHG for TranslatePress Safe to Use in 2026?

Generally Safe

Score 100/100

HHG for TranslatePress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "hhg-for-translatepress" plugin version 1.0.4 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The plugin utilizes prepared statements for all SQL queries and exhibits excellent output escaping, with 99% of outputs properly handled. Furthermore, the absence of dangerous functions, file operations, and recorded vulnerabilities in its history are significant strengths. The plugin also implements nonce and capability checks, indicating an awareness of common WordPress security practices.

However, a couple of areas warrant attention. The presence of two AJAX handlers, even though they have associated capability checks, represents potential entry points that could be leveraged if the checks were ever to be bypassed or misconfigured. While no taint analysis issues were found, the plugin does make 8 external HTTP requests, which, without further context, introduces a potential for supply chain risks or reliance on external services that could be compromised. The lack of any recorded vulnerabilities is a positive sign, suggesting a history of secure development, but it is important to remember that this is based on available data and does not guarantee future immunity.

In conclusion, the plugin appears to be well-developed from a security perspective, with a minimal attack surface and good adherence to secure coding practices. The main areas to monitor would be the secure implementation of the AJAX handlers and the potential risks associated with external HTTP requests. The absence of historical vulnerabilities is a notable strength.

Key Concerns

  • AJAX handlers present
  • External HTTP requests made
Vulnerabilities
None known

HHG for TranslatePress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

HHG for TranslatePress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
89 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
8
Bundled Libraries
0

Output Escaping

99% escaped90 total outputs
Attack Surface

HHG for TranslatePress Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_hhgfotr_zhipu_test_apihhg-for-translatepress.php:87
authwp_ajax_hhg_zhipu_test_apihhg-for-translatepress.php:88
WordPress Hooks 14
actionadmin_noticeshhg-for-translatepress.php:43
actionplugins_loadedhhg-for-translatepress.php:46
actionplugins_loadedhhg-for-translatepress.php:74
filtertrp_machine_translation_engineshhg-for-translatepress.php:78
filtertrp_automatic_translation_engines_classeshhg-for-translatepress.php:79
filtertrp_automatic_translation_engines_classeshhg-for-translatepress.php:80
filtertrp_machine_translator_is_availablehhg-for-translatepress.php:81
filtertrp_machine_translation_sanitize_settingshhg-for-translatepress.php:82
actiontrp_machine_translation_extra_settings_middlehhg-for-translatepress.php:83
filtertrp_get_default_trp_machine_translation_settingshhg-for-translatepress.php:84
actionadmin_enqueue_scriptshhg-for-translatepress.php:85
filtertrp_machine_translation_sanitize_settingshhg-for-translatepress.php:86
actionhttp_api_debughhg-for-translatepress.php:191
actionwp_loadedhhg-for-translatepress.php:197
Maintenance & Trust

HHG for TranslatePress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 12, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs400
Developer Profile

HHG for TranslatePress Developer Profile

胡洪刚

1 plugin · 400 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HHG for TranslatePress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hhg-for-translatepress/assets/css/admin-style.css/wp-content/plugins/hhg-for-translatepress/assets/js/admin-script.js/wp-content/plugins/hhg-for-translatepress/assets/js/zhipu-api-test.js
Script Paths
/wp-content/plugins/hhg-for-translatepress/assets/js/admin-script.js/wp-content/plugins/hhg-for-translatepress/assets/js/zhipu-api-test.js
Version Parameters
/wp-content/plugins/hhg-for-translatepress/assets/css/admin-style.css?ver=/wp-content/plugins/hhg-for-translatepress/assets/js/admin-script.js?ver=/wp-content/plugins/hhg-for-translatepress/assets/js/zhipu-api-test.js?ver=

HTML / DOM Fingerprints

CSS Classes
hhgfotr-zhipu-api-test-results
Data Attributes
data-zhipu-api-test-nonce
JS Globals
hhgfotr_zhipu_api_test_nonce
REST Endpoints
/wp-json/hhgfotr/v1/zhipu_test_api
FAQ

Frequently Asked Questions about HHG for TranslatePress