
qTranslate Exporter Security & Risk Analysis
wordpress.org/plugins/qtranslate-exporterA simple plugin to enable the WordPress Exporter to export a specific qTranslate language with the correct content language.
Is qTranslate Exporter Safe to Use in 2026?
Generally Safe
Score 85/100qTranslate Exporter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The qtranslate-exporter v1.0 plugin exhibits a strong security posture in several key areas. Its static analysis reveals no AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface. Furthermore, it avoids dangerous functions, performs file operations, makes external HTTP requests, and utilizes nonce or capability checks, which are positive indicators of secure coding practices. The plugin also uses prepared statements for all SQL queries, mitigating SQL injection risks.
However, a significant concern arises from the taint analysis, which identified two flows with unsanitized paths. While no critical or high severity issues were found in these flows, the presence of unsanitized paths indicates a potential for vulnerabilities if user input is not handled meticulously. Additionally, the static analysis shows that 100% of its single output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if the output includes user-supplied data.
The plugin's vulnerability history is clean, with no recorded CVEs. This absence of past vulnerabilities, coupled with the lack of critical issues in the current analysis, suggests a generally secure codebase. However, the identified taint flows and unescaped output remain potential weaknesses that should be addressed to ensure a more robust security profile. Overall, qtranslate-exporter v1.0 demonstrates good practices by minimizing its attack surface and securing its database interactions, but it has clear areas for improvement in input sanitization and output escaping.
Key Concerns
- Flows with unsanitized paths found
- Output not properly escaped
- No nonce checks
- No capability checks
qTranslate Exporter Security Vulnerabilities
qTranslate Exporter Code Analysis
Output Escaping
Data Flow Analysis
qTranslate Exporter Attack Surface
WordPress Hooks 6
Maintenance & Trust
qTranslate Exporter Maintenance & Trust
Maintenance Signals
Community Trust
qTranslate Exporter Alternatives
All-in-One WP Migration and Backup
all-in-one-wp-migration
Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate, backup, and restore your WordPress site with one click.
Widget Importer & Exporter
widget-importer-exporter
Import and export your widgets.
WP Migrate Lite – Migration Made Easy
wp-migrate-db
Migrate your database. Export full sites including media, themes, and plugins. Find and replace content with support for serialized data.
Customizer Export/Import
customizer-export-import
Easily export or import your WordPress customizer settings!
Advanced Order Export For WooCommerce
woo-order-export-lite
Export WooCommerce orders to Excel, CSV, XML, JSON, PDF and HTML. Best free order export plugin for WooCommerce.
qTranslate Exporter Developer Profile
9 plugins · 8K total installs
How We Detect qTranslate Exporter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
qtranslate-exporter-settings