MK to Lat Security & Risk Analysis

wordpress.org/plugins/mk-to-lat

This plugin convert macedonian cyrillic characters in post titles into latin characters. You can use this plugin for creating human-readable links.

100 active installs v2.0 PHP + WP 2.0.2+ Updated May 20, 2008
convertcyrillicmacedoniamacedonianmk
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MK to Lat Safe to Use in 2026?

Generally Safe

Score 85/100

MK to Lat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 17yr ago
Risk Assessment

The "mk-to-lat" v2.0 plugin exhibits a strong security posture based on the provided static analysis data. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero total and zero unprotected entry points. This significantly limits the potential attack surface. Furthermore, the code signals indicate a lack of dangerous functions, file operations, external HTTP requests, and importantly, robust output escaping. The plugin also demonstrates a complete absence of vulnerability history, with no recorded CVEs, suggesting a history of secure development practices. The taint analysis further reinforces this, showing no identified flows with unsanitized paths. However, a notable concern is the presence of a single SQL query that does not utilize prepared statements. While the attack surface is minimal and other security indicators are positive, this could represent a potential injection vulnerability if the query's parameters are not meticulously sanitized elsewhere. Overall, this plugin appears highly secure with a minimal risk profile, primarily due to its limited entry points and good output escaping practices, with the sole area for improvement being the handling of SQL queries.

Key Concerns

  • SQL query without prepared statements
Vulnerabilities
None known

MK to Lat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MK to Lat Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries
Attack Surface

MK to Lat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionsanitize_titlemk-to-lat.php:31
Maintenance & Trust

MK to Lat Maintenance & Trust

Maintenance Signals

WordPress version tested2.5.1
Last updatedMay 20, 2008
PHP min version
Downloads71K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

MK to Lat Developer Profile

spiritfly

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MK to Lat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mk-to-lat/style.css/wp-content/plugins/mk-to-lat/js/mk-to-lat.js
Script Paths
/wp-content/plugins/mk-to-lat/js/mk-to-lat.js
Version Parameters
mk-to-lat/style.css?ver=mk-to-lat/js/mk-to-lat.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about MK to Lat