
Hreflang for polylang Security & Risk Analysis
wordpress.org/plugins/hreflang-for-polylangAuto print in header the link alternate hreflang of all the language in the website.
Is Hreflang for polylang Safe to Use in 2026?
Generally Safe
Score 85/100Hreflang for polylang has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hreflang-for-polylang" plugin v1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, file operations, or external HTTP requests is a positive indicator. Furthermore, all SQL queries utilize prepared statements, mitigating the risk of SQL injection vulnerabilities. The lack of any recorded CVEs or past vulnerabilities is also encouraging.
However, a significant concern arises from the output escaping analysis. With one total output identified and 0% properly escaped, this indicates a clear risk of cross-site scripting (XSS) vulnerabilities. Any data processed and displayed by this plugin that is not properly sanitized before output could be exploited by attackers to inject malicious scripts into users' browsers. The lack of any capability checks or nonce checks, while not directly indicated as a risk due to the absence of an attack surface, means that if any entry points were to be introduced in future versions, they would be unprotected.
In conclusion, while the plugin has a clean vulnerability history and avoids many common pitfalls, the critical lack of output escaping presents a tangible security risk. Addressing this specific issue should be the immediate priority to improve the plugin's overall security. The absence of known vulnerabilities suggests good development practices in other areas, but the XSS potential needs urgent attention.
Key Concerns
- Unescaped output identified
Hreflang for polylang Security Vulnerabilities
Hreflang for polylang Code Analysis
Output Escaping
Hreflang for polylang Attack Surface
WordPress Hooks 1
Maintenance & Trust
Hreflang for polylang Maintenance & Trust
Maintenance Signals
Community Trust
Hreflang for polylang Alternatives
Theme and plugin translation for Polylang (TTfP)
theme-translation-for-polylang
Theme and plugin translation using Polylang for WordPress. Extension for Polylang plugin.
Juiz Lang Attribute
juiz-lang-attributes
Add a custom HREFLANG meta box on your post to manually edit the link between your post and a translation (which could be outside your domain).
Language option for ACF4+ Fields
language-option-for-acf4-fields
Adding language option to ACF fields plugin.
Connect Polylang for Elementor
connect-polylang-elementor
Connect Polylang with Elementor: translated templates, language switcher widget, language visibility conditions and more
ACF Options For Polylang
acf-options-for-polylang
Improves Polylang by adding per-language support for ACF options pages—each language can have its own option values.
Hreflang for polylang Developer Profile
1 plugin · 100 total installs
How We Detect Hreflang for polylang
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.