wp-cleanumlauts2 Security & Risk Analysis

wordpress.org/plugins/wp-cleanumlauts2

Converts German umlauts for permalinks, post, comments, feeds automatically. Wandelt Umlaute automatisch für Permalinks, Posting, Kommentare, Feeds.

1K active installs v1.6 PHP + WP 2.7+ Updated Nov 28, 2017
deutschgermanumlautumlauteumlauts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is wp-cleanumlauts2 Safe to Use in 2026?

Generally Safe

Score 85/100

wp-cleanumlauts2 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'wp-cleanumlauts2' plugin v1.6 exhibits a seemingly robust security posture based on the provided static analysis. It reports zero attack surface entry points, no dangerous functions, and all SQL queries utilize prepared statements. Furthermore, there are no recorded vulnerabilities or CVEs associated with this plugin, suggesting a history of responsible development and maintenance.

However, a significant concern arises from the complete lack of output escaping, with 0% of the 7 detected outputs being properly sanitized. This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data could be injected into the output and executed in a victim's browser. While there are no overt taint flows or critical code signals, the unescaped output presents a clear and present danger that could be exploited.

In conclusion, while the plugin's architecture appears secure against common injection attacks like SQLi and has a clean vulnerability history, the pervasive issue of unescaped output is a critical weakness. This oversight could lead to significant security breaches, despite the plugin's otherwise strong security practices.

Key Concerns

  • No output escaping detected
Vulnerabilities
None known

wp-cleanumlauts2 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

wp-cleanumlauts2 Release Timeline

v1.5.0
v1.3.2
Code Analysis
Analyzed Mar 16, 2026

wp-cleanumlauts2 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

wp-cleanumlauts2 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionadmin_menuumlauts.php:57
actionadmin_initumlauts.php:60
filtersanitize_titleumlauts_core.php:73
filtersanitize_titleumlauts_core.php:74
filterthe_title_rssumlauts_core.php:79
filterthe_excerpt_rssumlauts_core.php:80
filterthe_content_rssumlauts_core.php:81
filterthe_titleumlauts_core.php:86
filterthe_excerptumlauts_core.php:87
filterthe_contentumlauts_core.php:88
filtercomment_textumlauts_core.php:89
filtercomment_authorumlauts_core.php:94
filtercomment_author_rssumlauts_core.php:95
filtercomment_author_linkumlauts_core.php:96
filtercomment_text_rssumlauts_core.php:97
Maintenance & Trust

wp-cleanumlauts2 Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedNov 28, 2017
PHP min version
Downloads43K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

wp-cleanumlauts2 Developer Profile

Juergen Schulze

7 plugins · 1K total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect wp-cleanumlauts2

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-cleanumlauts2/umlauts.php

HTML / DOM Fingerprints

HTML Comments
Copyright 2011 Juergen Schulze (email : 1manfactory@gmail.com)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License, version 2, aspublished by the Free Software Foundation.+7 more
Data Attributes
umlauts_options[activate_permalinks]umlauts_options[activate_feeds]umlauts_options[activate_posts]umlauts_options[activate_comments]umlauts_activate_permalinksumlauts_activate_feeds+2 more
FAQ

Frequently Asked Questions about wp-cleanumlauts2