
WPML2WPMSLS Security & Risk Analysis
wordpress.org/plugins/wpml2wpmslsConvert posts from an existing WPML multilingual site via WP Import/Export to a WPMS (Network) with Language Switcher so easily it feels like magic!
Is WPML2WPMSLS Safe to Use in 2026?
Generally Safe
Score 85/100WPML2WPMSLS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wpml2wpmsls" v0.2.0 plugin presents a concerning security posture, primarily due to a complete lack of output escaping. While the static analysis reveals no immediate critical vulnerabilities such as dangerous functions, SQL injection risks, or unsanitized file operations, the 100% unescaped output is a significant oversight. This means any dynamic data rendered by the plugin could be susceptible to cross-site scripting (XSS) attacks if user-supplied input is involved. The absence of any known CVEs and a clean vulnerability history is positive, suggesting a diligent approach to security in past development or a very limited feature set. However, the lack of comprehensive security checks like nonces and capability checks, coupled with zero identified attack surface entries in the static analysis, might indicate a very basic plugin or an incomplete static analysis. The absence of any taint flows or attack vectors in the static analysis should be viewed with caution, as this could simply mean the plugin's functionality does not lend itself to such vulnerabilities or that the analysis was limited.
In conclusion, the plugin's primary weakness lies in its output handling. While it avoids common critical vulnerabilities, the unescaped output creates a substantial XSS risk. The limited attack surface and clean vulnerability history are strengths, but they do not negate the critical need for proper output sanitization. Until this is addressed, the plugin should be considered a moderate risk, with the potential for XSS exploitation.
Key Concerns
- Output not properly escaped
WPML2WPMSLS Security Vulnerabilities
WPML2WPMSLS Release Timeline
WPML2WPMSLS Code Analysis
SQL Query Safety
Output Escaping
WPML2WPMSLS Attack Surface
WordPress Hooks 5
Maintenance & Trust
WPML2WPMSLS Maintenance & Trust
Maintenance Signals
Community Trust
WPML2WPMSLS Alternatives
WPML to Polylang
wpml-to-polylang
Import multilingual data from WPML into Polylang.
Falang WPML importer
falang-wpml-importer
Import multilingual data from WPML into Falang for Wordpress
Translate Multilingual sites – TranslatePress
translatepress-multilingual
Translate your entire site directly from the front-end and go multilingual. Full support for WooCommerce, page builders + Google Translate integration
Hyyan WooCommerce Polylang Integration
woo-poly-integration
Given that I am not using Wordpress these days and I haven't really been using WooPoly for a while. I am looking for maintainers to take over thi …
WPBakery Visual Composer & qTranslate-X
js-composer-qtranslate-x
Enables multilingual framework for plugin "WPBakery Visual Composer".
WPML2WPMSLS Developer Profile
1 plugin · 10 total installs
How We Detect WPML2WPMSLS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.