Ho YouDao Translate For TranslatePress Security & Risk Analysis

wordpress.org/plugins/ho-youdao-translate-for-translatepress

为TranslatePress添加有道翻译API支持,实现自动化翻译功能。

100 active installs v1.0.3 PHP 7.2+ WP 6.0+ Updated Jul 18, 2025
multilingualtranslatetranslatepresstranslationyoudao
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Ho YouDao Translate For TranslatePress Safe to Use in 2026?

Generally Safe

Score 100/100

Ho YouDao Translate For TranslatePress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "ho-you-dou-translate-for-translatepress" plugin, version 1.0.3, exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities in its history, coupled with the analysis showing no dangerous functions, unsanitized paths in taint analysis, and the use of prepared statements for all SQL queries, indicates a proactive approach to security by the developers. Furthermore, all identified output points are properly escaped, and there are no file operations, which are common sources of vulnerabilities.

However, a few areas warrant attention. The complete lack of nonce checks and capability checks for any potential entry points (though none are explicitly listed as unprotected) presents a theoretical risk. If any unlisted entry points were discovered or introduced in future versions, they would be vulnerable. The single external HTTP request, while not inherently a vulnerability, requires careful scrutiny to ensure it is making requests to trusted endpoints and not exposing sensitive data. The plugin also has a remarkably small attack surface, which is a positive, but the absence of any security checks on these entry points is a notable weakness.

In conclusion, while the plugin appears secure due to the absence of known vulnerabilities and good coding practices in critical areas, the lack of explicit security checks on its entry points and the single external HTTP request represent minor potential weaknesses. The consistent lack of vulnerabilities over time is a significant strength. Future updates should aim to introduce nonce and capability checks if any entry points are identified.

Key Concerns

  • No nonce checks present
  • No capability checks present
  • External HTTP requests made
Vulnerabilities
None known

Ho YouDao Translate For TranslatePress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ho YouDao Translate For TranslatePress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped17 total outputs
Attack Surface

Ho YouDao Translate For TranslatePress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_noticesho-youdao-translate-for-translatepress.php:29
actionplugins_loadedho-youdao-translate-for-translatepress.php:54
filtertrp_machine_translation_enginesinc\ServiceProvider\RegisterMachineTranslationEngines.php:19
filtertrp_automatic_translation_engines_classesinc\ServiceProvider\RegisterMachineTranslationEngines.php:20
actiontrp_machine_translation_extra_settings_middleinc\ServiceProvider\RegisterMachineTranslationEngines.php:21
actiontrp_machine_translation_sanitize_settingsinc\ServiceProvider\RegisterMachineTranslationEngines.php:22
filtertrp_youdao_target_languageinc\ServiceProvider\RegisterMachineTranslationEngines.php:25
filtertrp_youdao_source_languageinc\ServiceProvider\RegisterMachineTranslationEngines.php:26
actionadmin_enqueue_scriptsinc\ServiceProvider\RegisterScripts.php:13
Maintenance & Trust

Ho YouDao Translate For TranslatePress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 18, 2025
PHP min version7.2
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Ho YouDao Translate For TranslatePress Developer Profile

Hollis

2 plugins · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ho YouDao Translate For TranslatePress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ho-youdao-translate-for-translatepress/assets/js/trp-back-end-script-youdao.js
Version Parameters
ho-youdao-translate-for-translatepress/assets/js/trp-back-end-script-youdao.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Ho YouDao Translate For TranslatePress