
SDAC Translate Security & Risk Analysis
wordpress.org/plugins/sdac-translateSimple lightweight translation sidebar widget that uses Google Translation.
Is SDAC Translate Safe to Use in 2026?
Generally Safe
Score 85/100SDAC Translate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sdac-translate plugin v1.2.6 exhibits a mixed security posture. On the positive side, there are no known CVEs, and all detected SQL queries utilize prepared statements, which is an excellent practice. The absence of file operations and external HTTP requests also reduces the attack surface. However, the code analysis reveals significant concerns. The presence of the `create_function` PHP construct is a critical security risk, as it can be exploited for arbitrary code execution. Furthermore, a substantial 44% of output is not properly escaped, leaving the plugin vulnerable to cross-site scripting (XSS) attacks when user-supplied data is displayed. The complete lack of nonce and capability checks across all potential entry points (though currently reported as zero, this could change with future updates or if the reporting mechanism is incomplete) is a serious oversight, as it leaves any future exposed functionality unprotected against common web attacks.
The plugin's vulnerability history is currently clean, with no recorded CVEs. This, combined with the use of prepared statements, might suggest a good development track record or a small user base that has not yet attracted significant attention from vulnerability researchers. However, the presence of the `create_function` and the high rate of unescaped output are fundamental security flaws that are independent of historical vulnerability data and require immediate attention. The plugin has strengths in its handling of database queries and lack of external interactions, but its susceptibility to code execution and XSS due to poor escaping and dangerous function usage are critical weaknesses.
Key Concerns
- Use of dangerous function: create_function
- High percentage of unescaped output
- Missing nonce checks
- Missing capability checks
SDAC Translate Security Vulnerabilities
SDAC Translate Code Analysis
Dangerous Functions Found
Output Escaping
SDAC Translate Attack Surface
WordPress Hooks 6
Maintenance & Trust
SDAC Translate Maintenance & Trust
Maintenance Signals
Community Trust
SDAC Translate Alternatives
Ls Gtrans Widget
ls-gtrans-widget
Widget with a select box for Google translation of the current page. Includes more than 25 European languages.
LocoAI – Auto Translate For Loco Translate
automatic-translator-addon-for-loco-translate
LocoAI - Auto Translate For Loco Translate is a powerful tool for developers looking to quickly translate their WordPress plugins and themes.
Prisna GWT – Google Website Translator
google-website-translator
Easily translate your WordPress site into 100+ languages to make it multilingual. A simple and complete multilingual solution for WordPress.
Advanced Google Translate
advanced-google-translate
Advanced Google Translate plugin.
TranslateX for Loco Translate
translatex-for-loco-translate
Integrate the TranslateX automatic translator API with the Loco Translate plugin for seamless, neural machine translations.
SDAC Translate Developer Profile
4 plugins · 40 total installs
How We Detect SDAC Translate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sdac-translate/css/sdac-translate.css/wp-content/plugins/sdac-translate/css/sdac-translate_admin.css/sdac-translate/js/jquery.ui.widget.js/sdac-translate/js/jquery.ui.accordion.jsHTML / DOM Fingerprints
sdac_translate_optionsdac_flagid="sdac_translate"name="sdac_translate[site_language]"name="sdac_translate[show_type]"name="sdac_translate[Albanian_show]"name="sdac_translate[Arabic_show]"name="sdac_translate[Bulgarian_show]"+40 morejQuery