
Zanto WP Translation (For Multisites) Security & Risk Analysis
wordpress.org/plugins/zantoZanto WP Translation helps you run a multilingual site by providing linkage between content in blogs of different languages in a WordPress multisite.
Is Zanto WP Translation (For Multisites) Safe to Use in 2026?
Generally Safe
Score 85/100Zanto WP Translation (For Multisites) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "zanto" v0.3.4 plugin exhibits significant security concerns due to its unprotected entry points and a concerning lack of output sanitization. While the plugin demonstrates some good practices, such as a high percentage of prepared SQL statements and a substantial number of nonce and capability checks, these are overshadowed by critical vulnerabilities identified in the static and taint analysis. The presence of unprotected AJAX handlers presents a direct attack vector, especially when combined with a high number of unsanitized paths detected in the taint analysis. The low percentage of properly escaped output is particularly alarming, suggesting a high risk of cross-site scripting (XSS) vulnerabilities that could be exploited by attackers. The absence of known CVEs is a positive sign, but it does not negate the internal code quality issues that pose a substantial risk to users. The plugin's overall security posture is therefore weak, with critical vulnerabilities in code execution paths and output handling that require immediate attention.
Key Concerns
- 2 unprotected AJAX handlers
- 11 flows with unsanitized paths
- 6 critical severity taint flows
- Only 20% of output properly escaped
- 1 dangerous function (unserialize)
Zanto WP Translation (For Multisites) Security Vulnerabilities
Zanto WP Translation (For Multisites) Release Timeline
Zanto WP Translation (For Multisites) Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Zanto WP Translation (For Multisites) Attack Surface
AJAX Handlers 2
WordPress Hooks 80
Maintenance & Trust
Zanto WP Translation (For Multisites) Maintenance & Trust
Maintenance Signals
Community Trust
Zanto WP Translation (For Multisites) Alternatives
BuddyPress Extended Profile Translation
buddypress-extended-profile-translation
Multilingual Extended Profiles in multisite BuddyPress
EffortLess Multisite Language Switcher
effortless-multisite-language-switcher
Adds a floating globe icon to WordPress Multisite to switch between different languages or subsites easily.
LingoJS – Website Translation Integration
lingojs-website-translation-integration
Easily integrate LingoJS into your WordPress site for fast and automatic multilingual translation.
WPMMCC
wpmmcc
Automatic multilingual translation for WordPress — posts, pages, media, categories, themes — powered by Google, DeepL, Baidu, Youdao or OpenAI.
Polylang
polylang
Go multilingual in a simple and efficient way. Keep writing posts and taxonomy terms as usual while defining their languages all at once.
Zanto WP Translation (For Multisites) Developer Profile
9 plugins · 350 total installs
How We Detect Zanto WP Translation (For Multisites)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zanto/javascript/zanto-main.js/wp-content/plugins/zanto/javascript/zanto-installation.js/wp-content/plugins/zanto/javascript/mo-management.js/wp-content/plugins/zanto/javascript/jquery.cookie.js/wp-content/plugins/zanto/javascript/browser-lang-redirect.js/wp-content/plugins/zanto/css/admin.css/wp-content/plugins/zanto/css/icon-font/css/font-awesome.min.cssjavascript/zanto-main.jsjavascript/zanto-installation.jsjavascript/mo-management.jsjavascript/jquery.cookie.jsjavascript/browser-lang-redirect.jszanto-translation-main?ver=0.3.4zanto-installation?ver=0.3.4mo-management?ver=0.3.4jquery_cookie?ver=0.3.4browser_lang_redirect?ver=0.3.4admin?ver=0.3.4icon_font/css/font-awesome.min.css?ver=0.3.4HTML / DOM Fingerprints
zwt_admindata-idzwt_main_i8nZanto_WT