WP Permalink Translator Security & Risk Analysis

wordpress.org/plugins/wp-permalink-translator

Allow admins to translate Permalink to another languages.

2K active installs v1.7.6 PHP + WP 4.0+ Updated Feb 16, 2019
permalinkpermalink-translatortranslator
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEJun 27, 2025
Safety Verdict

Is WP Permalink Translator Safe to Use in 2026?

Use With Caution

Score 63/100

WP Permalink Translator has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jun 27, 2025Updated 7yr ago
Risk Assessment

The wp-permalink-translator plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no identified entry points like AJAX handlers, REST API routes, or shortcodes that are unprotected. Furthermore, all SQL queries utilize prepared statements, and there are no detected taint flows with unsanitized paths, suggesting good practices in these areas. The presence of a capability check, though only one, is also a positive sign.

However, significant concerns arise from the vulnerability history. The existence of one unpatched medium severity CVE is a critical red flag. The fact that this is the *last* known vulnerability and is currently unpatched, with a CVE date in the very near future (2025-06-27), strongly suggests a persistent or recurring security issue. The static analysis also highlights a weakness in output escaping, with only 33% of outputs being properly escaped, which could lead to XSS vulnerabilities if user-supplied data is outputted without proper sanitization. The presence of file operations without further context is also a potential area for concern.

In conclusion, while the plugin appears to have a small attack surface and good practices regarding SQL queries and taint analysis, the unpatched CVE and the significant portion of unescaped output represent substantial security risks. The plugin's history and current state warrant caution and prompt action to address the outstanding vulnerability.

Key Concerns

  • Unpatched CVE (medium severity)
  • Low output escaping percentage (33%)
Vulnerabilities
1

WP Permalink Translator Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-53274medium · 4.3Cross-Site Request Forgery (CSRF)

WP Permalink Translator <= 1.7.6 - Cross-Site Request Forgery

Jun 27, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

WP Permalink Translator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped6 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
wp_permalink_translator (wp-permalink-translator.php:32)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Permalink Translator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuwp-permalink-translator.php:11
actionplugins_loadedwp-permalink-translator.php:12
filtersanitize_titlewp-permalink-translator.php:376
actiontransition_post_statuswp-permalink-translator.php:471
Maintenance & Trust

WP Permalink Translator Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedFeb 16, 2019
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings4
Active installs2K
Developer Profile

WP Permalink Translator Developer Profile

Hossin Asaadi

1 plugin · 2K total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Permalink Translator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-permalink-translator/css/style.css
Version Parameters
wp-permalink-translator/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wrapnoticenotice-successis-dismissiblenotice-dismissscreen-reader-text
Data Attributes
data-nonce-value
FAQ

Frequently Asked Questions about WP Permalink Translator