
WP Permalink Translator Security & Risk Analysis
wordpress.org/plugins/wp-permalink-translatorAllow admins to translate Permalink to another languages.
Is WP Permalink Translator Safe to Use in 2026?
Use With Caution
Score 63/100WP Permalink Translator has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wp-permalink-translator plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no identified entry points like AJAX handlers, REST API routes, or shortcodes that are unprotected. Furthermore, all SQL queries utilize prepared statements, and there are no detected taint flows with unsanitized paths, suggesting good practices in these areas. The presence of a capability check, though only one, is also a positive sign.
However, significant concerns arise from the vulnerability history. The existence of one unpatched medium severity CVE is a critical red flag. The fact that this is the *last* known vulnerability and is currently unpatched, with a CVE date in the very near future (2025-06-27), strongly suggests a persistent or recurring security issue. The static analysis also highlights a weakness in output escaping, with only 33% of outputs being properly escaped, which could lead to XSS vulnerabilities if user-supplied data is outputted without proper sanitization. The presence of file operations without further context is also a potential area for concern.
In conclusion, while the plugin appears to have a small attack surface and good practices regarding SQL queries and taint analysis, the unpatched CVE and the significant portion of unescaped output represent substantial security risks. The plugin's history and current state warrant caution and prompt action to address the outstanding vulnerability.
Key Concerns
- Unpatched CVE (medium severity)
- Low output escaping percentage (33%)
WP Permalink Translator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Permalink Translator <= 1.7.6 - Cross-Site Request Forgery
WP Permalink Translator Code Analysis
Output Escaping
Data Flow Analysis
WP Permalink Translator Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP Permalink Translator Maintenance & Trust
Maintenance Signals
Community Trust
WP Permalink Translator Alternatives
WP-Parsi Permalink Translator
wp-parsi-permalink-translator
Automatic translate post title for use as slug
Translate WordPress with GTranslate
gtranslate
Translate WordPress with Google Translate multilanguage plugin to make your website multilingual. Complete multilingual SEO solution for WordPress.
Custom Post Type Permalinks
custom-post-type-permalinks
Edit the permalink of custom post type.
Custom Permalinks
custom-permalinks
A powerful WordPress plugin for full URL control. Set custom permalinks, auto-redirects, and use dynamic tags for ideal site structure and SEO.
Translate WordPress – Google Language Translator
google-language-translator
Translate WordPress with Google Language Translator multilanguage plugin which allows to insert Google Translate widget anywhere on your website.
WP Permalink Translator Developer Profile
1 plugin · 2K total installs
How We Detect WP Permalink Translator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-permalink-translator/css/style.csswp-permalink-translator/css/style.css?ver=HTML / DOM Fingerprints
wrapnoticenotice-successis-dismissiblenotice-dismissscreen-reader-textdata-nonce-value