
ICanLocalize Translator Security & Risk Analysis
wordpress.org/plugins/icanlocalize-translatorAllows running multilingual WordPress sites with zero management. Automatically creates and updates translation when you edit.
Is ICanLocalize Translator Safe to Use in 2026?
Generally Safe
Score 85/100ICanLocalize Translator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The icanlocalize-translator v1.3.1 plugin exhibits a concerning security posture despite having no recorded historical vulnerabilities. The static analysis reveals several significant weaknesses that warrant attention. While the plugin has a zero attack surface in terms of accessible entry points like AJAX handlers, REST API routes, or shortcodes, this is overshadowed by critical code-level issues.
The presence of dangerous functions like `shell_exec` and `unserialize` is a major red flag, especially when combined with a low percentage of properly escaped output (only 25%) and a complete absence of nonce and capability checks. The taint analysis further highlights risks, with all analyzed flows (4 out of 4) showing unsanitized paths and 3 of those being of high severity. This strongly suggests potential for code injection or other serious vulnerabilities if user-supplied data can reach these dangerous functions without proper sanitization and validation.
The plugin's clean vulnerability history might indicate good development practices or simply a lack of public discovery. However, the current static analysis findings are too severe to ignore. The combination of dangerous functions, poor output escaping, lack of authorization checks, and identified high-severity taint flows presents a significant risk. While the plugin has no known CVEs, the internal code quality issues indicate a high potential for newly discovered vulnerabilities.
Key Concerns
- Dangerous functions (shell_exec, unserialize)
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
- High severity taint flows
- SQL queries with low prepared statement usage
- Flows with unsanitized paths
ICanLocalize Translator Security Vulnerabilities
ICanLocalize Translator Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
ICanLocalize Translator Attack Surface
WordPress Hooks 17
Maintenance & Trust
ICanLocalize Translator Maintenance & Trust
Maintenance Signals
Community Trust
ICanLocalize Translator Alternatives
Multilify
multilify
Powerful multilingual content management for WordPress with custom slugs and SEO optimization.
Loco Translate
loco-translate
Translate WordPress plugins and themes directly in your browser. Versatile PO file editor with integrated AI translation providers.
Polylang
polylang
Go multilingual in a simple and efficient way. Keep writing posts and taxonomy terms as usual while defining their languages all at once.
WP Multilang – Translation and Multilingual Plugin
wp-multilang
Multilingual plugin for WordPress. Go Multilingual in minutes with full WordPress support. Translate your site easily with this localization plugin.
Preferred Languages
preferred-languages
Choose languages for displaying WordPress in, in order of preference.
ICanLocalize Translator Developer Profile
9 plugins · 108K total installs
How We Detect ICanLocalize Translator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/icanlocalize-translator/inc/icanlocalize.css/wp-content/plugins/icanlocalize-translator/inc/icanlocalize.js/wp-content/plugins/icanlocalize-translator/inc/icanlocalize.jsicanlocalize-translator/inc/icanlocalize.css?ver=icanlocalize-translator/inc/icanlocalize.js?ver=HTML / DOM Fingerprints
lang_sel_seldata-icl-languageICanLocalizeiclt_language_selector<div id="lang_sel">