
Simple Slug Translate Security & Risk Analysis
wordpress.org/plugins/simple-slug-translateSimple Slug Translate can translate the post, page, category and taxonomy slugs to English automatically.
Is Simple Slug Translate Safe to Use in 2026?
Generally Safe
Score 85/100Simple Slug Translate has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of simple-slug-translate v2.7.3 reveals a generally positive security posture with no identified critical or high-severity code signals or taint flows. The absence of dangerous functions, SQL queries without prepared statements, and file operations is commendable. However, there are areas for improvement. A notable concern is the lack of nonce checks and capability checks across all identified entry points. While the current attack surface appears small and all entry points are protected by some form of authentication or permission, the absence of explicit nonce and capability checks on potentially sensitive operations could still present a risk if any authentication bypass is possible or if the permission checks are not robust enough.
The vulnerability history indicates that the plugin has had a past Cross-site Scripting (XSS) vulnerability, which was patched. The fact that there are no currently unpatched CVEs is a good sign. However, the existence of past XSS vulnerabilities suggests that input sanitization and output escaping, while at 78% for outputs, could be more thorough to prevent recurrence. The external HTTP request also warrants attention, as it could be a vector for further exploitation if not handled securely.
In conclusion, simple-slug-translate v2.7.3 demonstrates good practices in many areas, particularly in avoiding dangerous functions and using prepared statements for SQL. The plugin also appears to have addressed past vulnerabilities promptly. The primary weaknesses lie in the lack of explicit nonce and capability checks on its entry points and the history of XSS vulnerabilities, which, despite being patched, highlights the importance of vigilant input validation and output escaping. Further hardening in these areas would significantly improve its security.
Key Concerns
- 0 Nonce checks on entry points
- 0 Capability checks on entry points
- 22% of output not properly escaped
- 1 External HTTP request
- 1 Medium severity CVE historically
Simple Slug Translate Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Slug Translate <= 2.7.2 - Authenticated (Administrator+) Stored Cross-Site Scritping
Simple Slug Translate Code Analysis
Output Escaping
Simple Slug Translate Attack Surface
WordPress Hooks 5
Maintenance & Trust
Simple Slug Translate Maintenance & Trust
Maintenance Signals
Community Trust
Simple Slug Translate Alternatives
Translate WordPress with GTranslate
gtranslate
Translate WordPress with Google Translate multilanguage plugin to make your website multilingual. Complete multilingual SEO solution for WordPress.
Polylang
polylang
Go multilingual in a simple and efficient way. Keep writing posts and taxonomy terms as usual while defining their languages all at once.
Translate Multilingual sites – TranslatePress
translatepress-multilingual
Translate your entire site directly from the front-end and go multilingual. Full support for WooCommerce, page builders + Google Translate integration
Cyr-To-Lat
cyr2lat
Convert Non-Latin characters in post, page and term slugs to Latin characters.
Translate WordPress – Google Language Translator
google-language-translator
Translate WordPress with Google Language Translator multilanguage plugin which allows to insert Google Translate widget anywhere on your website.
Simple Slug Translate Developer Profile
5 plugins · 2K total installs
How We Detect Simple Slug Translate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-slug-translate/css/admin.css/wp-content/plugins/simple-slug-translate/js/admin.js/wp-content/plugins/simple-slug-translate/js/admin.jssimple-slug-translate/css/admin.css?ver=simple-slug-translate/js/admin.js?ver=