Localize – Website Translation Integration Security & Risk Analysis

wordpress.org/plugins/localizejs

Translate your WordPress site into multiple languages in minutes.

40 active installs v1.3.5 PHP 8.0+ WP 5.0+ Updated Feb 24, 2026
languagelocalizelocalizejstranslatetranslations
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Localize – Website Translation Integration Safe to Use in 2026?

Generally Safe

Score 100/100

Localize – Website Translation Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'localizejs' v1.3.5 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of identifiable attack surface points like AJAX handlers, REST API routes, shortcodes, and cron events, coupled with zero critical or high severity taint analysis findings, suggests a well-contained plugin. Furthermore, the code demonstrates good practices with 100% of SQL queries using prepared statements and all output being properly escaped, indicating a low risk of common injection and cross-site scripting vulnerabilities.

While the static analysis reveals no immediate code-level risks, the presence of one external HTTP request warrants attention. Without knowing the target or purpose of this request, it represents a potential, albeit minor, avenue for information disclosure or interaction with untrusted third-party services. The plugin's history of zero known CVEs is a significant positive indicator, suggesting consistent security development and maintenance by its authors. However, the lack of any recorded vulnerability history, while generally good, also means there's no precedent for how the developers address security issues, making future responses somewhat of an unknown. Overall, 'localizejs' v1.3.5 appears to be a secure plugin with minimal risk, primarily due to its lack of exploitable entry points and adherence to secure coding practices, with the external HTTP request being the only area requiring potential cautious monitoring.

Key Concerns

  • External HTTP request present
Vulnerabilities
None known

Localize – Website Translation Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Localize – Website Translation Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Attack Surface

Localize – Website Translation Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actioninitlocalizejs.php:43
actionwp_enqueue_scriptslocalizejs.php:48
actionadmin_menulocalizejs.php:49
actionadmin_initlocalizejs.php:50
filterwalker_nav_menu_start_ellocalizejs.php:98
filterpage_linklocalizejs.php:357
filterpost_linklocalizejs.php:358
filterterm_linklocalizejs.php:359
filterpost_type_archive_linklocalizejs.php:360
filterday_linklocalizejs.php:361
filtermonth_linklocalizejs.php:362
filteryear_linklocalizejs.php:363
filterhome_urllocalizejs.php:364
filterthe_contentlocalizejs.php:375
filteroption_homelocalizejs.php:379
filterthe_contentlocalizejs.php:384
filteroption_homelocalizejs.php:388
actioninitlocalizejs.php:394
Maintenance & Trust

Localize – Website Translation Integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 24, 2026
PHP min version8.0
Downloads10K

Community Trust

Rating100/100
Number of ratings4
Active installs40
Developer Profile

Localize – Website Translation Integration Developer Profile

johnnylocalizejs

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Localize – Website Translation Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/localizejs/localizejs.js
Script Paths
//global.localizecdn.com/localize.js

HTML / DOM Fingerprints

JS Globals
PROJECT_KEYURL_OPTIONSALLOW_INLINE_BREAK_TAGSAUTO_APPROVERETRANSLATE_ON_NEW_PHRASESOVERRIDE_LANG+3 more
FAQ

Frequently Asked Questions about Localize – Website Translation Integration