
Theme and plugin translation for Polylang (TTfP) Security & Risk Analysis
wordpress.org/plugins/theme-translation-for-polylangTheme and plugin translation using Polylang for WordPress. Extension for Polylang plugin.
Is Theme and plugin translation for Polylang (TTfP) Safe to Use in 2026?
Generally Safe
Score 92/100Theme and plugin translation for Polylang (TTfP) has a strong security track record. Known vulnerabilities have been patched promptly.
The "theme-translation-for-polylang" plugin, version 3.4.9, presents a mixed security posture. On the positive side, there are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-point attack surface. Furthermore, all SQL queries utilize prepared statements, and there are no external HTTP requests, which are excellent security practices. However, a significant concern arises from the taint analysis, which shows three flows with unsanitized paths. While no critical or high severity issues were flagged from these flows, this indicates a potential for directory traversal or file path manipulation vulnerabilities, especially given the presence of file operations. The plugin's vulnerability history includes one past medium-severity vulnerability related to missing authorization, which is a recurring theme in WordPress plugin security and warrants attention. Despite the lack of immediate critical threats from the current analysis, the unsanitized path flows and the history of authorization issues suggest that the plugin could be improved in terms of input validation and privilege checking to ensure a more robust security profile.
Key Concerns
- Taint flows with unsanitized paths
- Output escaping is not fully implemented
- Past medium vulnerability (Missing Authorization)
- No nonce checks detected
Theme and plugin translation for Polylang (TTfP) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Theme and plugin translation for Polylang <= 3.2.16 - Missing Authorization
Theme and plugin translation for Polylang (TTfP) Code Analysis
Output Escaping
Data Flow Analysis
Theme and plugin translation for Polylang (TTfP) Attack Surface
WordPress Hooks 14
Maintenance & Trust
Theme and plugin translation for Polylang (TTfP) Maintenance & Trust
Maintenance Signals
Community Trust
Theme and plugin translation for Polylang (TTfP) Alternatives
WP Multilang – Translation and Multilingual Plugin
wp-multilang
Multilingual plugin for WordPress. Go Multilingual in minutes with full WordPress support. Translate your site easily with this localization plugin.
Polylang Theme Strings
polylang-theme-strings
Automatic scanning of strings translation in the theme and registration of them in Polylang plugin. Extension for Polylang plugin.
AutoPoly – AI Translation For Polylang
automatic-translations-for-polylang
AI Translation For Polylang simplifies your translation process by automatically translating all pages/posts content from one language to another.
Multilanguage by BestWebSoft – WordPress Translation Plugin and Language Switcher
multilanguage
The ultimate WordPress translation solution with built-in language translator. Create multilingual content, switch languages, and translate your entir …
Translate Gravity Forms x Polylang
translate-gravity-forms-x-polylang
Add form titles, descriptions, field labels, etc. to Polylang string translations
Theme and plugin translation for Polylang (TTfP) Developer Profile
1 plugin · 10K total installs
How We Detect Theme and plugin translation for Polylang (TTfP)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/theme-translation-for-polylang/css/admin.css/wp-content/plugins/theme-translation-for-polylang/js/admin.js/wp-content/plugins/theme-translation-for-polylang/js/admin.jstheme-translation-for-polylang/css/admin.css?ver=theme-translation-for-polylang/js/admin.js?ver=HTML / DOM Fingerprints
notice-successnotice-erroris-dismissibledata-pll_actionPowered by Theme and plugin translation for Polylang (TTfP)