WP Slug Post Type Custom Language (Polylang) Security & Risk Analysis

wordpress.org/plugins/wp-slug-post-type-custom-language

Change your internal URLs (Slug) of your custom Post Type to the desired language of the system (Polylang).

300 active installs v1.0.7 PHP + WP 3.5+ Updated Dec 24, 2022
languagepolylangpost-custompost_typeslug
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Slug Post Type Custom Language (Polylang) Safe to Use in 2026?

Generally Safe

Score 85/100

WP Slug Post Type Custom Language (Polylang) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "wp-slug-post-type-custom-language" v1.0.7 plugin exhibits a strong security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, or cron events, and a complete lack of unprotected entry points significantly limits its attack surface. The code signals further reinforce this positive assessment, with no dangerous functions identified, all SQL queries utilizing prepared statements, and a high percentage of output properly escaped. The presence of nonce and capability checks, though few, indicates some awareness of security best practices.

While the plugin demonstrates good practices in many areas, the low count of nonce and capability checks (5 and 3 respectively) could be a potential concern if the plugin's functionality expands in future versions. However, the taint analysis shows no critical or high severity unsanitized flows, and the vulnerability history is completely clean, with zero known CVEs. This suggests a well-written and secure codebase that has historically avoided security issues.

In conclusion, the "wp-slug-post-type-custom-language" v1.0.7 plugin appears to be highly secure with no immediate critical vulnerabilities detected. Its strengths lie in its minimal attack surface and robust handling of SQL queries and output escaping. The lack of any historical vulnerabilities further bolsters confidence. The only minor area for potential improvement might be an increased implementation of nonce and capability checks as the plugin evolves, though this is not a current identified risk.

Vulnerabilities
None known

WP Slug Post Type Custom Language (Polylang) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Slug Post Type Custom Language (Polylang) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
101 escaped
Nonce Checks
5
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped115 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
crrq_edit_language_page_callback (inc\edit-custom-slug-language.php:3)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Slug Post Type Custom Language (Polylang) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuwp-slug-post-type-custom-language.php:40
actioninitwp-slug-post-type-custom-language.php:42
actionafter_setup_themewp-slug-post-type-custom-language.php:49
actioninitwp-slug-post-type-custom-language.php:244
Maintenance & Trust

WP Slug Post Type Custom Language (Polylang) Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 24, 2022
PHP min version
Downloads7K

Community Trust

Rating84/100
Number of ratings6
Active installs300
Developer Profile

WP Slug Post Type Custom Language (Polylang) Developer Profile

carlosramosweb

4 plugins · 700 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Slug Post Type Custom Language (Polylang)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP Slug Post Type Custom Language (Polylang)