
WD Translator Security & Risk Analysis
wordpress.org/plugins/wd-translatorWebsite translation with Google Translate and OpenAI GPT support. Add a language switcher widget to translate your site content.
Is WD Translator Safe to Use in 2026?
Generally Safe
Score 100/100WD Translator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wd-translator" v1.0.0 plugin presents a generally good security posture, adhering to several best practices. The absence of critical or high-severity taint flows, a low percentage of SQL queries not using prepared statements, and a very high rate of output escaping are positive indicators. The plugin also demonstrates a limited attack surface with no identified unprotected entry points in the static analysis. The clean vulnerability history with zero known CVEs further contributes to its perceived safety.
However, a significant concern is the complete absence of nonce checks. While the static analysis shows no unprotected AJAX or REST API routes, the lack of nonces means that even if these endpoints were to be accessed by an authenticated user, they are still susceptible to Cross-Site Request Forgery (CSRF) attacks if not otherwise protected by capability checks. Additionally, the plugin makes external HTTP requests, which could be a vector for SSRF vulnerabilities if not handled with extreme care and validation of user-supplied data. The presence of two shortcodes, while not immediately problematic without further context, represents potential entry points that should ideally be accompanied by nonce checks or robust capability checks to prevent misuse.
Overall, the plugin exhibits strengths in output sanitization and SQL query safety. The lack of known historical vulnerabilities is encouraging. Nevertheless, the complete omission of nonce checks is a notable weakness that increases the risk of CSRF attacks. The external HTTP requests also warrant attention. A balanced conclusion suggests a plugin that is on the right track but has critical security mechanisms missing that require immediate attention.
Key Concerns
- No nonce checks detected
- External HTTP requests made
WD Translator Security Vulnerabilities
WD Translator Code Analysis
SQL Query Safety
Output Escaping
WD Translator Attack Surface
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
WD Translator Maintenance & Trust
Maintenance Signals
Community Trust
WD Translator Alternatives
Translate3K – Browser Language Switcher
translate3k-browser-language-switcher
Adds a language selector for automatic page translation using Google Translate.
Translation Helper
translation-helper
Easily translate WordPress websites with Google Translate API integration for multilingual content.
LocoAI – Auto Translate For Loco Translate
automatic-translator-addon-for-loco-translate
LocoAI - Auto Translate For Loco Translate is a powerful tool for developers looking to quickly translate their WordPress plugins and themes.
Prisna GWT – Google Website Translator
google-website-translator
Easily translate your WordPress site into 100+ languages to make it multilingual. A simple and complete multilingual solution for WordPress.
Ailo – AI Slug Translator
haayal-ai-slug-translator
Automatically translate non-English slugs into clean, user-friendly English to improve sharing and SEO.
WD Translator Developer Profile
3 plugins · 10 total installs
How We Detect WD Translator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wd-translator/public/css/flags.css/wp-content/plugins/wd-translator/public/css/wd-translator.css/wp-content/plugins/wd-translator/public/js/wd-translator.js/wp-content/plugins/wd-translator/public/js/wd-translator.jswd-translator/public/css/flags.css?ver=wd-translator/public/css/wd-translator.css?ver=wd-translator/public/js/wd-translator.js?ver=HTML / DOM Fingerprints
wd-translator-widgetwd-translator-flags-containerwd-translator-language-dropdowndata-wd-translator-optionswdTranslatorSettings