
KeymanWeb Security & Risk Analysis
wordpress.org/plugins/keymanwebEnable custom keyboard input methodology in various input fields using your free Tavultesoft KeymanWeb Subscription
Is KeymanWeb Safe to Use in 2026?
Generally Safe
Score 85/100KeymanWeb has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "keymanweb" plugin v0.2 presents a mixed security posture. On the positive side, the plugin exhibits no known CVEs, a history of no past vulnerabilities, and a reported absence of dangerous functions, direct SQL queries, file operations, external HTTP requests, and bundled libraries. This suggests a relatively clean and minimal codebase.
However, significant concerns arise from the static analysis. The plugin has zero output escaping implemented, meaning all 6 identified output points are potentially vulnerable to cross-site scripting (XSS) attacks. While the taint analysis shows no critical or high-severity unsanitized flows, the presence of 2 flows with unsanitized paths, even if not flagged as critical, warrants attention, especially when coupled with the complete lack of output escaping. The absence of nonce checks and capability checks, while not directly tied to an immediate exploit path in this analysis, represents a lack of standard WordPress security practices that could be exploited in conjunction with other weaknesses.
Overall, while the plugin's small attack surface and lack of known vulnerabilities are positive, the complete failure in output escaping is a critical flaw. The 2 unsanitized taint flows, although not classified as high-severity, compound this risk. Future development should prioritize proper output sanitization and consider implementing standard WordPress security checks like nonces and capability checks.
Key Concerns
- 0% output escaping
- 2 flows with unsanitized paths
- 0 nonce checks
- 0 capability checks
KeymanWeb Security Vulnerabilities
KeymanWeb Code Analysis
Output Escaping
Data Flow Analysis
KeymanWeb Attack Surface
WordPress Hooks 6
Maintenance & Trust
KeymanWeb Maintenance & Trust
Maintenance Signals
Community Trust
KeymanWeb Alternatives
WP Slug Post Type Custom Language (Polylang)
wp-slug-post-type-custom-language
Change your internal URLs (Slug) of your custom Post Type to the desired language of the system (Polylang).
Advanced Custom Fields: WPML Language Selector Field
advanced-custom-fields-wpml-language-selector
Custom field addon for Advanced Custom Fields plugin which provides a list of used WPML languages on website.
Language Code Classification
language-code
This plugin adds the ability to add an ISO 639-3 language code to the custom field of a post.
Post Title Furigana
post-title-furigana
Automatically set Japanese Reading title into the custom field.
WPGoogleLangTransliteration
wp-google-lang-transliteration
WPGoogleLangTransliteration Plugin offers Complete language transliteration support for your wordpress blogs.
KeymanWeb Developer Profile
1 plugin · 10 total installs
How We Detect KeymanWeb
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/keymanweb/keymanweb.phpHTML / DOM Fingerprints
keymanweb-messageid='keymanweb-message'id='KeymanWebControl'id='kmwico_a'KeymanWeb_inserted