Polylang Category Creator Security & Risk Analysis

wordpress.org/plugins/polylang-category-creator

Polylang extension to create categories for all languages in one page. It detects your languages and taxonomies to get things done easier.

80 active installs v1.5 PHP + WP 4.6.1+ Updated Dec 6, 2017
bulkmultiple-categoriespolylangtaxonomywoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Polylang Category Creator Safe to Use in 2026?

Generally Safe

Score 85/100

Polylang Category Creator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of the 'polylang-category-creator' v1.5 plugin reveals a generally strong security posture. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly positive. Furthermore, the plugin demonstrates good practice with the presence of nonce and capability checks, indicating an awareness of common WordPress security vulnerabilities. The zero reported CVEs and lack of historical vulnerabilities further reinforce this positive outlook, suggesting a well-maintained and secure codebase. However, a key area of concern is the output escaping, where only 42% of outputs are properly escaped. This leaves a significant portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not sufficiently sanitized before being displayed. While the attack surface is commendably small and protected, this weakness in output escaping represents a notable risk that needs attention.

Key Concerns

  • Output escaping is only 42% properly done
Vulnerabilities
None known

Polylang Category Creator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Polylang Category Creator Release Timeline

v1.5Current
v1.4
Code Analysis
Analyzed Mar 16, 2026

Polylang Category Creator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

42% escaped12 total outputs
Attack Surface

Polylang Category Creator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuadmin\admin-page.php:5
actioninitPolylang Category Creator.php:20
Maintenance & Trust

Polylang Category Creator Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedDec 6, 2017
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs80
Developer Profile

Polylang Category Creator Developer Profile

merk_cat

2 plugins · 90 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Polylang Category Creator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/polylang-category-creator/admin/js/main.js/wp-content/plugins/polylang-category-creator/admin/css/style.css
Script Paths
/wp-content/plugins/polylang-category-creator/admin/js/main.js
Version Parameters
polylang-category-creator/admin/js/main.js?ver=polylang-category-creator/admin/css/style.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Polylang Category Creator