Scriptoria – Auto Translate EN to ES Security & Risk Analysis

wordpress.org/plugins/scriptoria-auto-translate-en-to-es

Automatically translates website content from English to Spanish for visitors using the Google Translate API. Secure and lightweight.

0 active installs v1.1.1 PHP + WP 5.5+ Updated Oct 23, 2025
automatic-translationdynamic-contentelementorgoogle-translatetranslate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Scriptoria – Auto Translate EN to ES Safe to Use in 2026?

Generally Safe

Score 100/100

Scriptoria – Auto Translate EN to ES has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "scriptoria-auto-translate-en-to-es" v1.1.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of critical issues like dangerous functions, unsanitized taint flows, and a clean vulnerability history are positive indicators. The plugin also demonstrates good practices by having a limited attack surface with only two AJAX entry points, and critically, none of these appear to be exposed without authentication checks. The high percentage of properly escaped output further strengthens its security. However, there are a couple of areas that warrant attention. All six SQL queries are executed without prepared statements, which can expose the plugin to SQL injection vulnerabilities if the inputs used in these queries are not meticulously sanitized elsewhere. Additionally, while there is one nonce check, the complete lack of capability checks for its entry points is a significant concern, potentially allowing unauthorized users to trigger plugin functionality.

Overall, the plugin's strengths lie in its small attack surface, good output escaping, and lack of known historical vulnerabilities. The primary weaknesses are the reliance on non-prepared SQL statements and the absence of capability checks on its entry points. While the current version has no recorded vulnerabilities, the identified code signals suggest potential risks that could be exploited if not addressed. A balanced conclusion is that the plugin is relatively secure, but the lack of capability checks and the un-prepared SQL queries present exploitable pathways that should be remediated to achieve a more robust security posture.

Key Concerns

  • All SQL queries use prepared statements
  • No capability checks for entry points
  • 1 Nonce check present
  • Limited attack surface, no unprotected entry points
  • High percentage of properly escaped output
  • No known CVEs
  • No dangerous functions
  • No taint flows with unsanitized paths
  • No file operations
  • 1 External HTTP request
  • No shortcodes
  • No cron events
  • SQL queries without prepared statements
Vulnerabilities
None known

Scriptoria – Auto Translate EN to ES Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Scriptoria – Auto Translate EN to ES Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
0 prepared
Unescaped Output
1
14 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared6 total queries

Output Escaping

93% escaped15 total outputs
Attack Surface

Scriptoria – Auto Translate EN to ES Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_larmaries_translate_securescriptoria-auto-translate-en-to-es.php:376
noprivwp_ajax_larmaries_translate_securescriptoria-auto-translate-en-to-es.php:377
WordPress Hooks 4
actionwp_enqueue_scriptsscriptoria-auto-translate-en-to-es.php:223
actionadmin_initscriptoria-auto-translate-en-to-es.php:252
actionadmin_menuscriptoria-auto-translate-en-to-es.php:275
actionadmin_enqueue_scriptsscriptoria-auto-translate-en-to-es.php:288
Maintenance & Trust

Scriptoria – Auto Translate EN to ES Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 23, 2025
PHP min version
Downloads148

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Scriptoria – Auto Translate EN to ES Developer Profile

larmaries

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Scriptoria – Auto Translate EN to ES

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Scriptoria – Auto Translate EN to ES