
Multilingual Text Security & Risk Analysis
wordpress.org/plugins/multilingual-textWith this plugin you can have a text in multiple languages. Easy to use, no requirements.
Is Multilingual Text Safe to Use in 2026?
Generally Safe
Score 85/100Multilingual Text has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The multilingual-text plugin v1.4 exhibits a mixed security posture. On one hand, it demonstrates strong practices regarding SQL injection by utilizing prepared statements exclusively and has no recorded vulnerability history or known CVEs. The absence of file operations and external HTTP requests is also a positive indicator. However, the static analysis reveals significant concerns. The presence of 8 instances of the `create_function` is a major red flag, as this deprecated and potentially dangerous function can be a source of severe vulnerabilities if not handled with extreme care. Furthermore, the complete lack of output escaping across all 12 identified output points is a critical weakness, opening the door for Cross-Site Scripting (XSS) attacks. The complete absence of nonce and capability checks on any potential entry points, while the entry point count is zero in this analysis, suggests a general lack of security hardening that could become problematic if the attack surface expands or if the analysis missed certain pathways.
While the plugin currently has no known vulnerabilities and shows good database security, the identified code signals point to substantial risks that could be exploited. The reliance on `create_function` and the pervasive lack of output escaping are critical vulnerabilities. The absence of any recorded historical vulnerabilities might suggest either luck, a small user base, or that previous versions did not have these issues. However, the current version's code analysis presents immediate threats that outweigh the lack of past issues. It is crucial to address these identified code-level weaknesses to improve the plugin's overall security.
Key Concerns
- Dangerous function create_function usage
- All output unescaped (XSS risk)
- Missing nonce checks
- Missing capability checks
Multilingual Text Security Vulnerabilities
Multilingual Text Code Analysis
Dangerous Functions Found
Output Escaping
Multilingual Text Attack Surface
WordPress Hooks 11
Maintenance & Trust
Multilingual Text Maintenance & Trust
Maintenance Signals
Community Trust
Multilingual Text Alternatives
WP Multilang – Translation and Multilingual Plugin
wp-multilang
Multilingual plugin for WordPress. Go Multilingual in minutes with full WordPress support. Translate your site easily with this localization plugin.
WPGlobus
wpglobus
Multilingual/Globalization: URL-based multilanguage with an easy translation interface.
WPBakery Visual Composer & qTranslate-X
js-composer-qtranslate-x
Enables multilingual framework for plugin "WPBakery Visual Composer".
Sublanguage
sublanguage
Sublanguage is a lightweight multilanguage plugin for wordpress.
Falang for Elementor Lite
falang-for-elementor-lite
The Falang for Elementor plugin makes your Elementor page translation simpler.
Multilingual Text Developer Profile
6 plugins · 1K total installs
How We Detect Multilingual Text
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multilingual-text/flags/gb.png/wp-content/plugins/multilingual-text/flags/de.pngHTML / DOM Fingerprints
multilingual_textmultilingual_text_textsmultilingual_text_flags