
Transliterado Security & Risk Analysis
wordpress.org/plugins/transliteradoThis plugin gives better transliteration of non-ASCII characters in slugs.
Is Transliterado Safe to Use in 2026?
Generally Safe
Score 85/100Transliterado has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the transliterado plugin v0.8 reveals a generally good security posture with no identified attack surface in terms of AJAX handlers, REST API routes, shortcodes, or cron events. The absence of dangerous functions and external HTTP requests is also a positive sign. However, significant concerns arise from the SQL query handling, where 100% of queries are not using prepared statements, increasing the risk of SQL injection vulnerabilities. Furthermore, the output escaping is severely lacking, with only 13% of outputs properly escaped, leaving the plugin susceptible to cross-site scripting (XSS) attacks. The taint analysis also shows a concerning two flows with unsanitized paths, indicating potential for improper handling of user-supplied data. The plugin's vulnerability history is clean, with no known CVEs, which is a strong indicator of past good security practices. Despite the clean history, the code-level issues identified in the static analysis are critical and require immediate attention to prevent potential security breaches. The lack of nonce and capability checks, while not explicitly penalized by the provided deduction scale for the given entry points, further contributes to a less robust security implementation.
Key Concerns
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- Flows with unsanitized paths
- No nonce checks
- No capability checks
Transliterado Security Vulnerabilities
Transliterado Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Transliterado Attack Surface
WordPress Hooks 2
Maintenance & Trust
Transliterado Maintenance & Trust
Maintenance Signals
Community Trust
Transliterado Alternatives
Performant Translations
performant-translations
Making internationalization/localization in WordPress faster than ever before.
Preferred Languages
preferred-languages
Choose languages for displaying WordPress in, in order of preference.
Translation Stats
translation-stats
Show plugins translation stats on your WordPress install.
Translator with Baidu Service
translator-with-baidu-service
Translate your site in many languages with this plugin from JoyBin, Inc. The translating service provider is Baidu.
YD Setup Locale
yd-setup-locale
Automatically sets up the WP language environment based on first part of url. Will setup XML lang attribute + $locale variable.
Transliterado Developer Profile
1 plugin · 300 total installs
How We Detect Transliterado
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
mceStatusbar