
qTranslate X Cleanup and WPML Import Security & Risk Analysis
wordpress.org/plugins/qtranslate-to-wpml-exportAllows a complete uninstall and cleanup of qTranslate X meta-tags or importing translations into WPML
Is qTranslate X Cleanup and WPML Import Safe to Use in 2026?
Generally Safe
Score 100/100qTranslate X Cleanup and WPML Import has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "qtranslate-to-wpml-export" plugin v3.0.2 presents a moderate security risk. While the static analysis indicates a lack of dangerous functions, SQL injection vulnerabilities through prepared statements, and no external HTTP requests, there are notable areas of concern. The presence of two AJAX handlers without authentication checks significantly increases the attack surface, as these can potentially be exploited by unauthenticated users. Furthermore, the low percentage of properly escaped output (11%) suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website.
The plugin's vulnerability history, including one medium-severity CVE, highlights a past tendency towards missing authorization issues. Although there are no currently unpatched vulnerabilities, this historical pattern, combined with the current finding of unprotected AJAX endpoints, suggests a recurring security weakness. The limited taint analysis (0 flows) is a positive sign, but it doesn't negate the risks identified in the attack surface and output escaping metrics.
In conclusion, "qtranslate-to-wpml-export" v3.0.2 has some positive security attributes, such as the absence of dangerous functions and a good rate of prepared SQL statements. However, the unprotected AJAX endpoints and inadequate output escaping are significant weaknesses that require immediate attention. The past vulnerability also warrants caution. Developers should prioritize implementing proper authentication and authorization checks for all AJAX endpoints and ensure all output is properly escaped to mitigate the identified risks.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- Missing capability checks
- Past medium severity CVE
qTranslate X Cleanup and WPML Import Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
qTranslate X Cleanup and WPML Import <= 3.0.1 - Missing Authorization via clean_ajx
qTranslate X Cleanup and WPML Import Release Timeline
qTranslate X Cleanup and WPML Import Code Analysis
SQL Query Safety
Output Escaping
qTranslate X Cleanup and WPML Import Attack Surface
AJAX Handlers 5
WordPress Hooks 3
Maintenance & Trust
qTranslate X Cleanup and WPML Import Maintenance & Trust
Maintenance Signals
Community Trust
qTranslate X Cleanup and WPML Import Alternatives
WPML Multilingual for BuddyPress and BuddyBoss
buddypress-multilingual
WPML Multilingual for BuddyPress and BuddyBoss allows BuddyPress and BuddyBoss sites to run fully multilingual using the WPML plugin.
qTranslate META
qtranslate-meta
For users of qTranslate, allows you to set multi-lingual META tags and a <title> override for your posts and pages.
WPML comment merging
wpml-comment-merging
This plugin merges comments from all WPML translations of the posts and pages, so that they all are displayed on each other.
Merged Comments for WPML
merged-comments-wpml
An updated version of the fixed version of the no longer maintained WPML Comment Merging plugin.
Loco Translate
loco-translate
Translate WordPress plugins and themes directly in your browser. Versatile PO file editor with integrated AI translation providers.
qTranslate X Cleanup and WPML Import Developer Profile
9 plugins · 108K total installs
How We Detect qTranslate X Cleanup and WPML Import
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qtranslate-to-wpml-export/js/scripts.jsjs/scripts.jsHTML / DOM Fingerprints
QT_IMPORTER_AJAXQT_IMPORTER_AJAX_URL