Quick Translate POT/PO/MO Security & Risk Analysis

wordpress.org/plugins/quick-translate-pot-po-mo

"Quick Translate POT/PO/MO" is a tool for generating and modifying WordPress plugin translation files.

20 active installs v2.2.0 PHP 7.4+ WP 5.0+ Updated Apr 7, 2026
editori18npotooltranslation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Quick Translate POT/PO/MO Safe to Use in 2026?

Generally Safe

Score 100/100

Quick Translate POT/PO/MO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "quick-translate-pot-po-mo" plugin v2.1.2 exhibits a generally strong security posture. The static analysis reveals a well-implemented approach to security controls, with no detected dangerous functions, all SQL queries utilizing prepared statements, and a very high percentage of properly escaped output. Crucially, all AJAX handlers and REST API routes (if any were present) appear to have proper authentication and capability checks, significantly reducing the attack surface.

Taint analysis shows zero flows with unsanitized paths, indicating that the plugin is likely not vulnerable to common injection attacks like path traversal or command injection through user-supplied data. The complete absence of known CVEs and past vulnerabilities further strengthens this positive assessment. The presence of file operations and external HTTP requests is noted, but without further context on how these are handled, their risk is not immediately quantifiable from this data alone. However, the strong security practices observed in other areas suggest these might also be implemented securely.

In conclusion, the "quick-translate-pot-po-mo" plugin v2.1.2 demonstrates a commitment to secure coding practices. The lack of critical or high-severity issues in static analysis and the clean vulnerability history are significant strengths. While the presence of file operations and external HTTP requests warrants careful manual review in a deeper dive, the available data points to a low-risk plugin.

Vulnerabilities
None known

Quick Translate POT/PO/MO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Quick Translate POT/PO/MO Release Timeline

v2.2.0Current
v2.1.2
v2.1.1
v2.1.0
v2.0.0
v1.1.1
v1.1.0
Code Analysis
Analyzed Mar 16, 2026

Quick Translate POT/PO/MO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
101 escaped
Nonce Checks
15
Capability Checks
16
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

97% escaped104 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

6 flows
auto_translator_ajax_save_key (po-auto-fill-helper.php:154)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Quick Translate POT/PO/MO Attack Surface

Entry Points15
Unprotected0

AJAX Handlers 15

authwp_ajax_auto_translator_save_keypo-auto-fill-helper.php:180
authwp_ajax_auto_translator_previewpo-auto-fill-helper.php:350
authwp_ajax_auto_translator_savepo-auto-fill-helper.php:492
authwp_ajax_mmpt_check_i18nquick-translate-pot-po-mo.php:57
authwp_ajax_mmpt_check_pot_filequick-translate-pot-po-mo.php:58
authwp_ajax_mmpt_check_po_filequick-translate-pot-po-mo.php:59
authwp_ajax_mmpt_check_mo_filequick-translate-pot-po-mo.php:60
authwp_ajax_mmpt_generate_potquick-translate-pot-po-mo.php:61
authwp_ajax_mmpt_generate_poquick-translate-pot-po-mo.php:62
authwp_ajax_mmpt_load_poquick-translate-pot-po-mo.php:63
authwp_ajax_mmpt_save_poquick-translate-pot-po-mo.php:64
authwp_ajax_mmpt_delete_mo_filequick-translate-pot-po-mo.php:65
authwp_ajax_mmpt_download_potquick-translate-pot-po-mo.php:66
authwp_ajax_mmpt_download_poquick-translate-pot-po-mo.php:67
authwp_ajax_mmpt_download_moquick-translate-pot-po-mo.php:68
WordPress Hooks 6
actionadmin_menupo-auto-fill-helper.php:32
actionadmin_initpo-auto-fill-helper.php:43
actionadmin_enqueue_scriptspo-auto-fill-helper.php:770
actionadmin_footerpo-auto-fill-helper.php:797
actionadmin_menuquick-translate-pot-po-mo.php:43
actionadmin_enqueue_scriptsquick-translate-pot-po-mo.php:52
Maintenance & Trust

Quick Translate POT/PO/MO Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 7, 2026
PHP min version7.4
Downloads609

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Quick Translate POT/PO/MO Developer Profile

Kasuga

8 plugins · 140 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Quick Translate POT/PO/MO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quick-translate-pot-po-mo/assets/qtppm-admin.css/wp-content/plugins/quick-translate-pot-po-mo/assets/qtppm-admin.js
Script Paths
/wp-content/plugins/quick-translate-pot-po-mo/assets/qtppm-admin.js
Version Parameters
quick-translate-pot-po-mo/assets/qtppm-admin.css?ver=quick-translate-pot-po-mo/assets/qtppm-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-plugin-slug
JS Globals
QuickTranslate
FAQ

Frequently Asked Questions about Quick Translate POT/PO/MO