
Language Code Classification Security & Risk Analysis
wordpress.org/plugins/language-codeThis plugin adds the ability to add an ISO 639-3 language code to the custom field of a post.
Is Language Code Classification Safe to Use in 2026?
Generally Safe
Score 85/100Language Code Classification has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "language-code" plugin v0.1.3 Beta exhibits a generally good security posture based on the provided static analysis. The plugin has no recorded vulnerabilities, which is a positive indicator. Furthermore, the attack surface is reported as zero, meaning there are no obvious entry points like AJAX handlers, REST API routes, shortcodes, or cron events that could be directly exploited. The presence of nonce and capability checks, along with a reasonable proportion of SQL queries using prepared statements, also suggests some level of security awareness in its development.
However, there are significant concerns that temper this positive outlook. A striking 100% of output escaping is missing. This is a critical flaw as it opens the door to Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data could be injected into the webpage and executed by other users' browsers. While taint analysis did not reveal any flows, the lack of output escaping means that any data that *does* flow into the output functions is potentially dangerous. The presence of file operations also warrants caution, especially without further context on their nature and any associated validation or sanitization.
In conclusion, while the plugin has a clean vulnerability history and a small attack surface, the complete lack of output escaping presents a high-risk scenario for XSS vulnerabilities. The file operation also needs further scrutiny. Developers should prioritize addressing the output escaping issues to mitigate these significant risks.
Key Concerns
- 100% of output escaping is missing
- File operations present
Language Code Classification Security Vulnerabilities
Language Code Classification Code Analysis
SQL Query Safety
Output Escaping
Language Code Classification Attack Surface
WordPress Hooks 6
Maintenance & Trust
Language Code Classification Maintenance & Trust
Maintenance Signals
Community Trust
Language Code Classification Alternatives
JSM Show Post Metadata
jsm-show-post-meta
Show post metadata (aka custom fields) in a metabox when editing posts / pages - a great tool for debugging issues with post metadata.
JSM Show User Metadata
jsm-show-user-meta
Show user metadata in a metabox when editing users - a great tool for debugging issues with user metadata.
JSM Show Order Metadata for WooCommerce HPOS
jsm-show-order-meta
Show WooCommerce order metadata in a metabox when editing HPOS orders - a great tool for debugging issues with HPOS order metadata.
Advanced Custom Fields: Real Media Library Folder Field
acf-real-media-library-field
Media library folder field for Advanced Custom Fields (ACF). Folder created by Real Media Library.
Advanced Custom Fields: WPML Language Selector Field
advanced-custom-fields-wpml-language-selector
Custom field addon for Advanced Custom Fields plugin which provides a list of used WPML languages on website.
Language Code Classification Developer Profile
1 plugin · 10 total installs
How We Detect Language Code Classification
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/language-code/autocompleter.css/wp-content/plugins/language-code/jquery.autocomplete.js/wp-content/plugins/language-code/jquery.autocomplete.jslanguage-code/jquery.autocomplete.js?ver=1.0HTML / DOM Fingerprints
<p id='lanuage_code'><strong>Language:</strong>