MisterTranslate Security & Risk Analysis

wordpress.org/plugins/mistertranslate

Translate WordPress, Elementor and WooCommerce with AI while preserving layout and design.

0 active installs v5.0.1 PHP 7.0+ WP 5.0+ Updated Mar 29, 2026
aielementormultilingualtranslationwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MisterTranslate Safe to Use in 2026?

Generally Safe

Score 100/100

MisterTranslate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

This plugin exhibits a strong security posture in several key areas, including the exclusive use of prepared statements for all SQL queries and the proper escaping of all outputs. The absence of known CVEs and a clean vulnerability history further contribute to its perceived safety. However, the static analysis reveals two taint flows with unsanitized paths, which represent a significant concern. While the report categorizes these as 'High severity' and not 'Critical', any unsanitized data flow can potentially lead to vulnerabilities if not handled with extreme care. The presence of these flows despite other good practices suggests a potential blind spot in the sanitization logic for specific user-supplied data.

Despite the positive aspects of secure coding practices like proper escaping and prepared statements, the identified taint flows with unsanitized paths introduce a notable risk. These flows should be treated with high priority for investigation and remediation. The plugin's clean historical record is reassuring, but it does not negate the immediate risks presented by the current static analysis. Overall, while the plugin has a solid foundation in secure coding, the two high-severity taint flows are a weakness that requires attention to maintain a robust security profile.

Key Concerns

  • Taint flows with unsanitized paths (High severity)
  • Taint flows with unsanitized paths (High severity)
Vulnerabilities
None known

MisterTranslate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MisterTranslate Release Timeline

v5.0.1Current
v5.0.0
v4.2.5
v4.2.4
v4.2.3
v4.2.2
v4.2.1
Code Analysis
Analyzed Mar 17, 2026

MisterTranslate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
16 prepared
Unescaped Output
0
112 escaped
Nonce Checks
15
Capability Checks
16
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared16 total queries

Output Escaping

100% escaped112 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
<admin-page> (templates\admin-page.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MisterTranslate Attack Surface

Entry Points12
Unprotected0

AJAX Handlers 12

authwp_ajax_mstrt_translate_pagemistertranslate.php:90
authwp_ajax_mstrt_translate_productmistertranslate.php:91
authwp_ajax_mstrt_translate_categorymistertranslate.php:92
authwp_ajax_mstrt_get_itemsmistertranslate.php:93
authwp_ajax_mstrt_check_balancemistertranslate.php:94
authwp_ajax_mstrt_estimate_costmistertranslate.php:97
authwp_ajax_mstrt_preview_contentmistertranslate.php:98
authwp_ajax_mstrt_detect_languagemistertranslate.php:99
authwp_ajax_mstrt_check_outdatedmistertranslate.php:100
authwp_ajax_mstrt_retranslatemistertranslate.php:101
authwp_ajax_mstrt_save_glossarymistertranslate.php:102
authwp_ajax_mstrt_get_glossarymistertranslate.php:103
WordPress Hooks 6
actionadmin_menumistertranslate.php:80
actionadmin_enqueue_scriptsmistertranslate.php:81
actioninitmistertranslate.php:106
filterpost_row_actionsmistertranslate.php:109
filterpage_row_actionsmistertranslate.php:110
actionplugins_loadedmistertranslate.php:2165
Maintenance & Trust

MisterTranslate Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 29, 2026
PHP min version7.0
Downloads427

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

MisterTranslate Developer Profile

mistertranslate

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MisterTranslate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mistertranslate/assets/admin.css/wp-content/plugins/mistertranslate/assets/admin.js/wp-content/plugins/mistertranslate/assets/elementor-integration.js/wp-content/plugins/mistertranslate/assets/frontend.js
Script Paths
/wp-content/plugins/mistertranslate/assets/admin.js/wp-content/plugins/mistertranslate/assets/elementor-integration.js/wp-content/plugins/mistertranslate/assets/frontend.js
Version Parameters
/wp-content/plugins/mistertranslate/assets/admin.css?ver=/wp-content/plugins/mistertranslate/assets/admin.js?ver=/wp-content/plugins/mistertranslate/assets/elementor-integration.js?ver=/wp-content/plugins/mistertranslate/assets/frontend.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-mstrt-iddata-mstrt-typedata-mstrt-original-contentdata-mstrt-translated-content
JS Globals
mstrtData
FAQ

Frequently Asked Questions about MisterTranslate