
mqTranslate Separate Comments Security & Risk Analysis
wordpress.org/plugins/mqtranslate-separate-commentsAutomatically separates the user comments by the language they viewed in the article.
Is mqTranslate Separate Comments Safe to Use in 2026?
Generally Safe
Score 85/100mqTranslate Separate Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mqtranslate-separate-comments plugin v1.2.4 demonstrates a generally good security posture based on the static analysis. It correctly uses prepared statements for all its SQL queries, indicating a strong defense against SQL injection. The presence of nonce checks and the absence of dangerous functions are also positive signs. However, the analysis reveals a significant concern regarding output escaping, with only 63% of outputs being properly escaped. This leaves room for potential Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is outputted without sufficient sanitization. Additionally, the complete lack of capability checks on its single AJAX handler is a critical oversight, as it means any authenticated user, regardless of their role, can trigger this functionality. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strength. Overall, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the unescaped outputs and unprotected AJAX endpoint represent notable risks that should be addressed.
Key Concerns
- Unprotected AJAX endpoint
- Inadequate output escaping
mqTranslate Separate Comments Security Vulnerabilities
mqTranslate Separate Comments Code Analysis
SQL Query Safety
Output Escaping
mqTranslate Separate Comments Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
mqTranslate Separate Comments Maintenance & Trust
Maintenance Signals
Community Trust
mqTranslate Separate Comments Alternatives
mqtranslate langcode widget selector
language-code-selector-mqtranslate
Plugin that creates a widget with a language switcher with language codes. It's compatible with qtranslate and mqtranslate plugin.
W2Q: WPML to qTranslate
w2q-wpml-to-qtranslate
Migrates WPML translations to qTranslate.
Integration of Yoast wordpress SEO module with mqtranslate module
wp-seo-yoast-integration-mq-translate
Integration between the popular Wordpress SEO module by Yoast and mqtranslate plugin (a fork of qtranslate that is updated).
mqTranslate Separate Comments Developer Profile
1 plugin · 10 total installs
How We Detect mqTranslate Separate Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mqtranslate-separate-comments/css/style.css/wp-content/plugins/mqtranslate-separate-comments/js/script.js/wp-content/plugins/mqtranslate-separate-comments/js/script.jsmqtranslate-separate-comments/css/style.css?ver=mqtranslate-separate-comments/js/script.js?ver=HTML / DOM Fingerprints
comment_xtraid="qTranslate_Separate_Comments_language"var qTC_languages