
Persian World Security & Risk Analysis
wordpress.org/plugins/persian-worldIt will turn WordPress , bbPress and BuddyPress into Persian !
Is Persian World Safe to Use in 2026?
Generally Safe
Score 85/100Persian World has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "persian-world" plugin v3.2.3 demonstrates a generally secure configuration in several key areas, most notably the complete absence of known vulnerabilities in its history and the exclusive use of prepared statements for SQL queries. The static analysis also indicates a very limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks. Furthermore, the absence of dangerous functions and file operations is a positive sign.
However, significant concerns arise from the output escaping. With 0% of the 8 total outputs being properly escaped, this presents a high risk of cross-site scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the frontend without proper sanitization could be exploited. Additionally, the taint analysis revealing 2 flows with unsanitized paths, even without a critical or high severity classification, warrants attention. While not explicitly categorized as critical, these flows indicate potential routes for malicious data to enter the application and could be exploited in conjunction with the unescaped output.
The plugin's vulnerability history is a strong positive, suggesting a history of secure development. Coupled with the lack of critical signals in the code analysis, this paints a picture of a plugin with the potential for good security practices. Nevertheless, the critical deficiency in output escaping cannot be overlooked and significantly impacts the overall security posture.
Key Concerns
- 0% of outputs properly escaped
- 2 flows with unsanitized paths
Persian World Security Vulnerabilities
Persian World Code Analysis
Output Escaping
Data Flow Analysis
Persian World Attack Surface
WordPress Hooks 19
Maintenance & Trust
Persian World Maintenance & Trust
Maintenance Signals
Community Trust
Persian World Alternatives
Polylang
polylang
Go multilingual in a simple and efficient way. Keep writing posts and taxonomy terms as usual while defining their languages all at once.
Performant Translations
performant-translations
Making internationalization/localization in WordPress faster than ever before.
WP Multilang – Translation and Multilingual Plugin
wp-multilang
Multilingual plugin for WordPress. Go Multilingual in minutes with full WordPress support. Translate your site easily with this localization plugin.
Preferred Languages
preferred-languages
Choose languages for displaying WordPress in, in order of preference.
wpLingua – Automatic translation – Translate and make website multilingual
wplingua
Make your websites multilingual and translate them automatically: no word limits, editable translations, SEO-friendly, no coding knowledge needed
Persian World Developer Profile
1 plugin · 20 total installs
How We Detect Persian World
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
postbox-containermetabox-holdermeta-box-sortablespostboxhandledivhndleinsidecheck accessname="select"window.locationdocument.getElementsByTagNameinput[i].checked<center><input type="checkbox" name="select" value="<td><center></center></td><button class="button" onClick="group_link();" >پاککردن گزینششدهها</button>