
Translate WordPress with Weglot – Multilingual AI Translation Security & Risk Analysis
wordpress.org/plugins/weglotTranslate WordPress sites with automatic AI translation into 110+ languages. Multilingual SEO, WooCommerce compatible, 110k+ sites.
Is Translate WordPress with Weglot – Multilingual AI Translation Safe to Use in 2026?
Generally Safe
Score 98/100Translate WordPress with Weglot – Multilingual AI Translation has a strong security track record. Known vulnerabilities have been patched promptly.
The Weglot plugin v5.4 presents a mixed security posture. While it demonstrates good practices in SQL query handling and output escaping, with 100% prepared statements and 88% properly escaped outputs, there are concerning areas. The presence of one unprotected AJAX handler represents a significant entry point that could be exploited without proper authentication. This is further highlighted by the taint analysis, which, despite a low volume of flows, reveals two instances of unsanitized paths. Although no critical or high severity taint flows were found, the fact that any unsanitized paths exist is a concern for potential XSS or path traversal vulnerabilities.
The plugin's vulnerability history, with two known medium severity CVEs related to Missing Authorization and Cross-site Scripting, is a significant indicator of past weaknesses. The absence of currently unpatched vulnerabilities is positive, but the recurring types of past vulnerabilities suggest a need for ongoing vigilance in code review and authorization checks. The most recent vulnerability being from late 2025, while a future date, suggests a historical pattern of medium-severity issues, not a current pressing concern for the provided version.
In conclusion, Weglot v5.4 has strengths in its data handling and output sanitization. However, the unprotected AJAX handler and past vulnerability patterns, particularly around authorization and XSS, warrant careful consideration. The plugin is not inherently insecure, but the identified entry point and historical context necessitate robust security monitoring and potentially further code hardening.
Key Concerns
- Unprotected AJAX handler found
- Taint flows with unsanitized paths (2 instances)
- 2 past medium CVEs (Missing Authorization, XSS)
Translate WordPress with Weglot – Multilingual AI Translation Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Translate WordPress and go Multilingual – Weglot <= 5.1 - Missing Authorization to Unauthenticated Limited Transient Deletion
Translate WordPress and go Multilingual – Weglot <= 4.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes
Translate WordPress with Weglot – Multilingual AI Translation Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Translate WordPress with Weglot – Multilingual AI Translation Attack Surface
AJAX Handlers 1
REST API Routes 1
Shortcodes 1
WordPress Hooks 96
Maintenance & Trust
Translate WordPress with Weglot – Multilingual AI Translation Maintenance & Trust
Maintenance Signals
Community Trust
Translate WordPress with Weglot – Multilingual AI Translation Alternatives
AI Translation For TranslatePress
automatic-translate-addon-for-translatepress
Auto-translate unlimited strings and characters using AI & Machine Translation tools without any external API Key!
Linguise – AI Automatic Multilingual Translation
linguise
Linguise is a top-quality automatic AI translation with a front-end translation editor. 5' install, SEO-optimized translations, 85+ languages
Translate Website & Rank Globally with SEO & GEO – MultiLipi AI Translation
multilipi-multilingual-seo
Make WordPress multilingual with AI. Translate website & rank globally using built-in SEO + GEO infrastructure (Hreflang, Schema) to grow traffic
Translate Multilingual sites – TranslatePress
translatepress-multilingual
Translate your entire site directly from the front-end and go multilingual. Full support for WooCommerce, page builders + Google Translate integration
LocoAI – Auto Translate For Loco Translate
automatic-translator-addon-for-loco-translate
LocoAI - Auto Translate For Loco Translate is a powerful tool for developers looking to quickly translate their WordPress plugins and themes.
Translate WordPress with Weglot – Multilingual AI Translation Developer Profile
1 plugin · 60K total installs
How We Detect Translate WordPress with Weglot – Multilingual AI Translation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/weglot/dist/app.js/wp-content/plugins/weglot/dist/weglot_selector.js/wp-content/plugins/weglot/dist/ Weglot_admin.js/wp-content/plugins/weglot/dist/ wegloT_menu.js/wp-content/plugins/weglot/dist/app.js/wp-content/plugins/weglot/dist/weglot_selector.js/wp-content/plugins/weglot/dist/ Weglot_admin.js/wp-content/plugins/weglot/dist/ wegloT_menu.jsweglot/dist/app.js?ver=weglot/dist/weglot_selector.js?ver=weglot/dist/ Weglot_admin.js?ver=weglot/dist/ wegloT_menu.js?ver=HTML / DOM Fingerprints
weglot-dropdownweglot-menu-itemsdata-weglotweglot_configuration[weglot_menu][weglot_selector]