
WP Bakery Multilanguage Security & Risk Analysis
wordpress.org/plugins/multilanguage-add-on-for-visual-composerThis is an add-on plugin for WPBakery Visual Composer that adds multilanguage support and functionality. Version 2.0 now also has automatic translatio …
Is WP Bakery Multilanguage Safe to Use in 2026?
Generally Safe
Score 85/100WP Bakery Multilanguage has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "multilanguage-add-on-for-visual-composer" plugin v2.1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries that are not prepared, file operations, external HTTP requests, and a clean taint analysis are all positive indicators. Furthermore, the plugin has no known historical vulnerabilities, which suggests a history of responsible development and maintenance. The large number of output escapings (54 total) is a good sign, though the percentage of properly escaped outputs (30%) is a notable concern.
Despite the positive indicators, the 30% proper escaping rate for output is a significant weakness. This suggests that a substantial portion of user-generated or dynamic content displayed by the plugin may not be adequately sanitized, leaving it vulnerable to cross-site scripting (XSS) attacks. While the static analysis did not directly flag any XSS vulnerabilities, this low escaping rate represents a clear risk. The lack of any capability checks, nonce checks, or apparent authentication on entry points (even though the attack surface is zero) could also be a latent concern if any entry points were to be introduced in future versions or if the static analysis was incomplete.
In conclusion, the plugin's core code appears robust against many common server-side vulnerabilities. However, the inadequate output escaping is a significant and actionable concern that requires immediate attention to prevent potential client-side attacks. The lack of historical vulnerabilities is a strength, but the present issue with output escaping highlights a weakness that needs to be addressed.
Key Concerns
- Low percentage of properly escaped output
WP Bakery Multilanguage Security Vulnerabilities
WP Bakery Multilanguage Code Analysis
Output Escaping
WP Bakery Multilanguage Attack Surface
WordPress Hooks 20
Maintenance & Trust
WP Bakery Multilanguage Maintenance & Trust
Maintenance Signals
Community Trust
WP Bakery Multilanguage Alternatives
Theme and plugin translation for Polylang (TTfP)
theme-translation-for-polylang
Theme and plugin translation using Polylang for WordPress. Extension for Polylang plugin.
WP Multilang – Translation and Multilingual Plugin
wp-multilang
Multilingual plugin for WordPress. Go Multilingual in minutes with full WordPress support. Translate your site easily with this localization plugin.
Multilanguage by BestWebSoft – WordPress Translation Plugin and Language Switcher
multilanguage
The ultimate WordPress translation solution with built-in language translator. Create multilingual content, switch languages, and translate your entir …
DeMomentSomTres Language
demomentsomtres-language
DeMomentSomTres is a brand new plugin devoted to automatically commute to user browser language for WPML websites.
WPML Translation Check
wpml-translation-check
This plugin for WPML enabled sites allows you to easily perform a language check (including language detection) on your translated content.
WP Bakery Multilanguage Developer Profile
3 plugins · 4K total installs
How We Detect WP Bakery Multilanguage
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/visual-composer-multilanguage/css/visual-composer-multilanguage-admin.css/wp-content/plugins/visual-composer-multilanguage/js/visual-composer-multilanguage-admin.js/wp-content/plugins/visual-composer-multilanguage/js/visual-composer-multilanguage-admin.jsvisual-composer-multilanguage/css/visual-composer-multilanguage-admin.css?ver=visual-composer-multilanguage/js/visual-composer-multilanguage-admin.js?ver=HTML / DOM Fingerprints
visual-composer-multilanguage