
SiteTran – Translate Your WordPress Site Security & Risk Analysis
wordpress.org/plugins/sitetranWordPress Translation Made Easy. Full SEO Benefits. No coding required. Low-cost usage-based pricing. Go global with SiteTran today!
Is SiteTran – Translate Your WordPress Site Safe to Use in 2026?
Generally Safe
Score 100/100SiteTran – Translate Your WordPress Site has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sitetran" plugin v1.3.5 presents a mixed security posture. While the plugin boasts no recorded historical vulnerabilities and avoids dangerous functions, SQL injection risks, and direct file operations, significant concerns arise from its attack surface and code analysis. A substantial 18 out of 20 total entry points lack authentication checks, primarily within its AJAX handlers. This wide-open access to backend functionality is a major security weakness. Furthermore, although a majority of SQL queries use prepared statements, the remaining queries could still be a vector for injection. The output escaping also shows room for improvement, with over a third of outputs not being properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities. The absence of any historical CVEs is positive, suggesting diligent maintenance or a lack of prior exploitation. However, the current static analysis findings, particularly the extensive unprotected AJAX handlers, indicate a high potential for exploitation if an attacker can identify and target these endpoints. The plugin needs significant hardening around its entry points to mitigate these risks.
Key Concerns
- Unprotected AJAX handlers
- Unescaped output
- Unprotected REST API routes
- SQL queries without prepared statements
- Limited nonce checks
SiteTran – Translate Your WordPress Site Security Vulnerabilities
SiteTran – Translate Your WordPress Site Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
SiteTran – Translate Your WordPress Site Attack Surface
AJAX Handlers 18
REST API Routes 1
Shortcodes 1
WordPress Hooks 18
Maintenance & Trust
SiteTran – Translate Your WordPress Site Maintenance & Trust
Maintenance Signals
Community Trust
SiteTran – Translate Your WordPress Site Alternatives
Polylang
polylang
Go multilingual in a simple and efficient way. Keep writing posts and taxonomy terms as usual while defining their languages all at once.
WP Multilang – Translation and Multilingual Plugin
wp-multilang
Multilingual plugin for WordPress. Go Multilingual in minutes with full WordPress support. Translate your site easily with this localization plugin.
WPGlobus
wpglobus
Multilingual/Globalization: URL-based multilanguage with an easy translation interface.
wpLingua – Automatic translation – Translate and make website multilingual
wplingua
Make your websites multilingual and translate them automatically: no word limits, editable translations, SEO-friendly, no coding knowledge needed
Geo Targetly Geo Translate
geo-targetly-geo-translate
Auto-translate and localize your website based on visitor location. Show the right language variant to the right user.
SiteTran – Translate Your WordPress Site Developer Profile
1 plugin · 30 total installs
How We Detect SiteTran – Translate Your WordPress Site
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sitetran/css/backend_style.css/wp-content/plugins/sitetran/css/tippy_light_theme_6.3.7.css/wp-content/plugins/sitetran/js/popperjs_core_2.11.8.min.js/wp-content/plugins/sitetran/js/tippyjs_6.3.7.min.js/wp-content/plugins/sitetran/js/backend.js//c.sitetran.com/widget/v3.jssitetran/css/backend_style.css?ver=sitetran/css/tippy_light_theme_6.3.7.css?ver=sitetran/js/popperjs_core_2.11.8.min.js?ver=sitetran/js/tippyjs_6.3.7.min.js?ver=sitetran/js/backend.js?ver=sitetran/widget/v3.js?ver=3.0.0HTML / DOM Fingerprints
sitetran_frontend_cssSITETRAN_js_variablessitetran_cm_settings/wp-json/sitetran-translate/v1