
Translatio Security & Risk Analysis
wordpress.org/plugins/tmy-globalizationMake your website multilingual ready at ease with live translation or with support of full translation cycle, with machine translation integration.
Is Translatio Safe to Use in 2026?
Generally Safe
Score 100/100Translatio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The tmy-globalization plugin version 2.3.0 exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices in output escaping and a reasonable percentage of prepared SQL statements, the lack of authentication checks on all its AJAX entry points creates a broad attack surface. This suggests a potential for unauthorized actions or data manipulation if these handlers can be triggered by unauthenticated users.
The taint analysis reveals two high-severity flows with unsanitized paths. This is a critical concern as it indicates potential vulnerabilities where user-supplied input could be processed in an unsafe manner, potentially leading to code execution or other severe impacts. The absence of any recorded vulnerability history might suggest a lack of past exploitation or disclosure, but it does not negate the risks identified in the static analysis.
In conclusion, the plugin has strengths in areas like output escaping and SQL preparation. However, the substantial number of unprotected AJAX handlers and the presence of high-severity taint flows are significant weaknesses that warrant immediate attention. The lack of known CVEs is positive, but the identified code signals demand remediation to ensure a robust security posture.
Key Concerns
- Unprotected AJAX handlers present
- High severity taint flows with unsanitized paths
- Dangerous function 'unserialize' used
- Some SQL queries not using prepared statements
- File operations without clear context
Translatio Security Vulnerabilities
Translatio Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Translatio Attack Surface
AJAX Handlers 10
WordPress Hooks 102
Maintenance & Trust
Translatio Maintenance & Trust
Maintenance Signals
Community Trust
Translatio Alternatives
Polylang
polylang
Go multilingual in a simple and efficient way. Keep writing posts and taxonomy terms as usual while defining their languages all at once.
WP Multilang – Translation and Multilingual Plugin
wp-multilang
Multilingual plugin for WordPress. Go Multilingual in minutes with full WordPress support. Translate your site easily with this localization plugin.
wpLingua – Automatic translation – Translate and make website multilingual
wplingua
Make your websites multilingual and translate them automatically: no word limits, editable translations, SEO-friendly, no coding knowledge needed
Smartcat Translator for WPML
smartcat-wpml
The easiest way to translate your WPML-enabled WordPress site into various languages.
ICanLocalize Translator
icanlocalize-translator
Allows running multilingual WordPress sites with zero management. Automatically creates and updates translation when you edit.
Translatio Developer Profile
1 plugin · 0 total installs
How We Detect Translatio
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tmy-globalization/css/tmy-g11n-admin-slugs-page.css/wp-content/plugins/tmy-globalization/css/tmy-g11n-admin.css/wp-content/plugins/tmy-globalization/js/tmy-g11n-admin-slugs-page.js/wp-content/plugins/tmy-globalization/js/tmy-g11n-admin.jstmy-g11n-admin-slugs-page.css?ver=tmy-g11n-admin.css?ver=tmy-g11n-admin-slugs-page.js?ver=tmy-g11n-admin.js?ver=