
non-latin attachments Security & Risk Analysis
wordpress.org/plugins/non-latin-attachmentsSpecific web server break non-latin filename. Wordpress don't touch attachment's filename. This plugin change filename to numbers.
Is non-latin attachments Safe to Use in 2026?
Generally Safe
Score 85/100non-latin attachments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "non-latin-attachments" v1.0 plugin presents a significant security risk due to its unprotected AJAX handlers. The static analysis reveals four AJAX endpoints, all of which lack authentication checks, creating a large and easily exploitable attack surface. Furthermore, the plugin demonstrates poor coding practices regarding data sanitization and output escaping. With 100% of SQL queries not using prepared statements and 0% of outputs being properly escaped, there's a high probability of SQL injection and cross-site scripting (XSS) vulnerabilities.
The absence of any recorded vulnerability history might suggest a lack of past exploitation or discovery, but this should not be interpreted as an indicator of inherent security. The current code analysis reveals critical weaknesses that could easily lead to vulnerabilities. The single flow with unsanitized paths, while not flagged as high or critical severity in the taint analysis, points to potential issues if user-supplied data is not handled carefully.
In conclusion, while the plugin has no known CVEs, the static analysis indicates a fragile security posture. The unprotected AJAX handlers, raw SQL queries, and unescaped output are substantial concerns that require immediate attention. The lack of a robust security foundation in this version makes it susceptible to common web attacks.
Key Concerns
- AJAX handlers without auth checks
- SQL queries not using prepared statements
- Output escaping not properly implemented
- Flow with unsanitized paths
- No nonce checks on AJAX handlers
non-latin attachments Security Vulnerabilities
non-latin attachments Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
non-latin attachments Attack Surface
AJAX Handlers 4
WordPress Hooks 3
Maintenance & Trust
non-latin attachments Maintenance & Trust
Maintenance Signals
Community Trust
non-latin attachments Alternatives
No alternatives data available yet.
non-latin attachments Developer Profile
3 plugins · 130 total installs
How We Detect non-latin attachments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/non-latin-attachments/non-latin.js/wp-content/plugins/non-latin-attachments/non-latin.jsnon-latin.js?ver=HTML / DOM Fingerprints
for GD bbPress Attachment파일명과 줄 번호는 파일 편집 권한이 있는 사람에게만 보입니다. 따로 권한을 변경하지 않았다면 파일 편집 권한은 파일 편집 권한은 관리자에게만 있습니다.nlfnlf