
HHG for TranslatePress Security & Risk Analysis
wordpress.org/plugins/hhg-for-translatepressAdd AI translation engines (Gemini, Hunyuan, OpenAI, GLM) to TranslatePress with multi-model support and beautiful interface.
Is HHG for TranslatePress Safe to Use in 2026?
Generally Safe
Score 100/100HHG for TranslatePress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hhg-for-translatepress" plugin version 1.0.4 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The plugin utilizes prepared statements for all SQL queries and exhibits excellent output escaping, with 99% of outputs properly handled. Furthermore, the absence of dangerous functions, file operations, and recorded vulnerabilities in its history are significant strengths. The plugin also implements nonce and capability checks, indicating an awareness of common WordPress security practices.
However, a couple of areas warrant attention. The presence of two AJAX handlers, even though they have associated capability checks, represents potential entry points that could be leveraged if the checks were ever to be bypassed or misconfigured. While no taint analysis issues were found, the plugin does make 8 external HTTP requests, which, without further context, introduces a potential for supply chain risks or reliance on external services that could be compromised. The lack of any recorded vulnerabilities is a positive sign, suggesting a history of secure development, but it is important to remember that this is based on available data and does not guarantee future immunity.
In conclusion, the plugin appears to be well-developed from a security perspective, with a minimal attack surface and good adherence to secure coding practices. The main areas to monitor would be the secure implementation of the AJAX handlers and the potential risks associated with external HTTP requests. The absence of historical vulnerabilities is a notable strength.
Key Concerns
- AJAX handlers present
- External HTTP requests made
HHG for TranslatePress Security Vulnerabilities
HHG for TranslatePress Code Analysis
Output Escaping
HHG for TranslatePress Attack Surface
AJAX Handlers 2
WordPress Hooks 14
Maintenance & Trust
HHG for TranslatePress Maintenance & Trust
Maintenance Signals
Community Trust
HHG for TranslatePress Alternatives
Lifegence AITranslator
lifegence-aitranslator
AI-powered automatic translation plugin using Google Gemini and OpenAI GPT. Translate your entire WordPress site into multiple languages instantly.
AI Translation For TranslatePress
automatic-translate-addon-for-translatepress
Auto-translate unlimited strings and characters using AI & Machine Translation tools without any external API Key!
Ailo – AI Slug Translator
haayal-ai-slug-translator
Automatically translate non-English slugs into clean, user-friendly English to improve sharing and SEO.
Ho YouDao Translate For TranslatePress
ho-youdao-translate-for-translatepress
为TranslatePress添加有道翻译API支持,实现自动化翻译功能。
Hollisho Integration with DeepSeek for TranslatePress
hollisho-integration-deepseek-for-translatepress
为TranslatePress添加DeepSeek AI支持,实现自动化翻译功能。
HHG for TranslatePress Developer Profile
1 plugin · 400 total installs
How We Detect HHG for TranslatePress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hhg-for-translatepress/assets/css/admin-style.css/wp-content/plugins/hhg-for-translatepress/assets/js/admin-script.js/wp-content/plugins/hhg-for-translatepress/assets/js/zhipu-api-test.js/wp-content/plugins/hhg-for-translatepress/assets/js/admin-script.js/wp-content/plugins/hhg-for-translatepress/assets/js/zhipu-api-test.js/wp-content/plugins/hhg-for-translatepress/assets/css/admin-style.css?ver=/wp-content/plugins/hhg-for-translatepress/assets/js/admin-script.js?ver=/wp-content/plugins/hhg-for-translatepress/assets/js/zhipu-api-test.js?ver=HTML / DOM Fingerprints
hhgfotr-zhipu-api-test-resultsdata-zhipu-api-test-noncehhgfotr_zhipu_api_test_nonce/wp-json/hhgfotr/v1/zhipu_test_api