
qTranslate META Security & Risk Analysis
wordpress.org/plugins/qtranslate-metaFor users of qTranslate, allows you to set multi-lingual META tags and a <title> override for your posts and pages.
Is qTranslate META Safe to Use in 2026?
Generally Safe
Score 85/100qTranslate META has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The qtranslate-meta plugin v1.0.2 exhibits a mixed security posture. On the positive side, it has a very small attack surface with no registered AJAX handlers, REST API routes, shortcodes, or cron events. All SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are good practices. The absence of any known CVEs or past vulnerabilities is also a strong indicator of a relatively secure development history.
However, there are significant concerns within the code. The presence of the `create_function` is a critical security risk, as it is highly susceptible to code injection vulnerabilities. Furthermore, the plugin has a very low rate of output escaping, with only 8% of outputs being properly escaped. This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks, especially given the lack of explicit entry points to analyze for, means that any potential future entry points or existing hidden ones could be exploited without proper authorization or validation.
While the plugin's vulnerability history is clean, the static analysis reveals critical weaknesses in code quality that could lead to severe vulnerabilities. The use of `create_function` and the poor output escaping are major red flags that overshadow the limited attack surface and clean vulnerability history. A thorough review and remediation of these code quality issues are strongly recommended.
Key Concerns
- Use of dangerous create_function
- Low percentage of properly escaped output
- No nonce checks found
- No capability checks found
qTranslate META Security Vulnerabilities
qTranslate META Release Timeline
qTranslate META Code Analysis
Dangerous Functions Found
Output Escaping
qTranslate META Attack Surface
WordPress Hooks 5
Maintenance & Trust
qTranslate META Maintenance & Trust
Maintenance Signals
Community Trust
qTranslate META Alternatives
Loco Translate
loco-translate
Translate WordPress plugins and themes directly in your browser. Versatile PO file editor with integrated AI translation providers.
WPBakery Visual Composer & qTranslate-X
js-composer-qtranslate-x
Enables multilingual framework for plugin "WPBakery Visual Composer".
qTranslate X Cleanup and WPML Import
qtranslate-to-wpml-export
Allows a complete uninstall and cleanup of qTranslate X meta-tags or importing translations into WPML
Events Made Easy & qTranslate-X
events-made-easy-qtranslate-x
Enables multilingual framework for plugin "Events Made Easy".
YD Setup Locale
yd-setup-locale
Automatically sets up the WP language environment based on first part of url. Will setup XML lang attribute + $locale variable.
qTranslate META Developer Profile
2 plugins · 410 total installs
How We Detect qTranslate META
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qtranslate-meta/styles.cssHTML / DOM Fingerprints
qtrans_meta_language-switcherqtrans_meta_tableid="qtrans_meta_language_"name="qtrans_meta_title_"id="qtrans_meta_title_"name="qtrans_meta_keywords_"id="qtrans_meta_keywords_"name="qtrans_meta_description_"+2 moreqtrans_meta_switch_langqtrans_meta_count_chars