
Multilingual Comments Security & Risk Analysis
wordpress.org/plugins/multilingual-commentsMultilingual Comments is an add-on for WPML / WooCommerce. This plugin makes it possible via its own plugin settings, to show: comments on blog posts …
Is Multilingual Comments Safe to Use in 2026?
Generally Safe
Score 85/100Multilingual Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The multilingual-comments v1.0.1 plugin exhibits a generally positive security posture based on the provided static analysis. A notable strength is the complete absence of identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that lack proper authentication or capability checks. This significantly reduces the potential attack surface. Furthermore, the plugin does not appear to engage in risky operations like file manipulation or external HTTP requests. The limited number of SQL queries and the absence of taint analysis findings are also encouraging signs.
However, there are significant areas of concern that temper this positive outlook. The fact that 100% of the single SQL query is not using prepared statements is a critical vulnerability. This presents a high risk of SQL injection, allowing attackers to manipulate database queries. Additionally, with only 50% of output escaping, there's a risk of cross-site scripting (XSS) vulnerabilities if the unescaped outputs are rendered in a web context. The complete lack of nonce checks and capability checks, while not directly exploitable due to the lack of entry points, indicates a potential oversight in robust security practice that could become a risk if new entry points are added in future versions without these checks.
The vulnerability history being entirely clean (0 known CVEs, 0 unpatched) is a positive indicator, suggesting the plugin has historically been maintained with security in mind or has not been a target for exploitation. However, this cannot compensate for the critical SQL injection and potential XSS risks identified in the current version's code. The overall conclusion is that while the plugin has a small attack surface and no known past vulnerabilities, the current version contains critical flaws related to SQL and output sanitization that require immediate attention.
Key Concerns
- SQL queries without prepared statements
- Unescaped output
- No nonce checks
- No capability checks
Multilingual Comments Security Vulnerabilities
Multilingual Comments Code Analysis
SQL Query Safety
Output Escaping
Multilingual Comments Attack Surface
WordPress Hooks 12
Maintenance & Trust
Multilingual Comments Maintenance & Trust
Maintenance Signals
Community Trust
Multilingual Comments Alternatives
WPML comment merging
wpml-comment-merging
This plugin merges comments from all WPML translations of the posts and pages, so that they all are displayed on each other.
Discussions Tab for WooCommerce Products
discussions-tab-for-woocommerce-products
Creates a discussions tab for WooCommerce products.
ST Product Review Generator
st-product-review-generator
Transform the way you manage product feedback with ST Product Review Generator by StrivioThemes — the ultimate solution for bringing your customer …
HNB Multi Currency for WPML
hnb-multi-currency-for-wpml
Adds additional exchange rates for WooCommerce Multilingual - HNB (Croatian National Bank) (via https://www.hnb.hr/hnb-api).
Taknalogy Reviews
taknalogy-reviews
Manages and displays reviews for woocommerce product pages. It uses reviews service from taknalogy.com Taknalogy Reviews Homepage.
Multilingual Comments Developer Profile
4 plugins · 1K total installs
How We Detect Multilingual Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multilingual-comments/css/multilingual-comments-admin.css/wp-content/plugins/multilingual-comments/js/multilingual-comments-admin.jsmultilingual-comments-admin.css?ver=multilingual-comments-admin.js?ver=HTML / DOM Fingerprints
wrapwpmlc-settings-groupdata-settings-group="wpmlc-settings-group"