WordPress.org

Ready to get started?Download WordPress

Plugin Reviews

gtrans

Make your website available to the world using Google Translate

Average Rating
3 stars
3.7 out of 5 stars
You are currently viewing the reviews that provided a rating of 1 star. Click here to see all reviews.
1 star
ATTENTION WP MODERATORS: Malware Backlinks and Fake Downloads
By , for WP 3.4.2

Baddddddddddd plugin!! WordPress moderators need to look at this.

1 star
Dont use!!! hidden rogue/packed javascript, phones home, and hidden backlinks
By , for WP 3.4

ROGUE JAVASCRIPT: Hidden by a packer located in gtrans.php

line 118:

eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\\b'+e(c)+'\\\b','g'),k[c]);return p}('6 7(a,b){n{4(2.9){3 c=2.9("o");c.p(b,f,f);a.q(c)}g{3 c=2.r();a.s(\'t\'+b,c)}}u(e){}}6 h(a){4(a.8)a=a.8;4(a==\'\')v;3 b=a.w(\'|\')[1];3 c;3 d=2.x(\'y\');z(3 i=0;i<d.5;i++)4(d[i].A==\'B-C-D\')c=d[i];4(2.j(\'k\')==E||2.j(\'k\').l.5==0||c.5==0||c.l.5==0){F(6(){h(a)},G)}g{c.8=b;7(c,\'m\');7(c,\'m\')}}',43,43,'||document|var|if|length|function|GTranslateFireEvent|value|createEvent||||||true|else|doGTranslate||getElementById|google_translate_element2|innerHTML|change|try|HTMLEvents|initEvent|dispatchEvent|createEventObject|fireEvent|on|catch|return|split|getElementsByTagName|select|for|className|goog|te|combo|null|setTimeout|500'.split('|'),0,{}));

###########################################

HIDDEN BACKLINK: Checks useragent against google
in gtrans.php

line 125 and 126

if(stripos($_SERVER["HTTP_USER_AGENT"], 'google') !== false)
$script = $script . '<p>Powered by GTranslate - multilingual website solutions.</p>';

###########################################

PHONING HOME: Posts obfuscated data to http://tdn.gtranslate.net/tdn-bin/save after loading remote javascript from http://tdn.gtranslate.net/tdn-bin/queue.js

line 122:

<script src="http://tdn.gtranslate.net/tdn-bin/queue.js" type="text/javascript"></script>

###########################################

The unpacked javascript looks like it fools the wordpress repository by increasing the downloads. It makes an ajax head call to the download url to automatically increase downloads. This guarantees that it becomes a "popular" plugin in the repo.

Shame shame shame..

1 star
Legal problems
By , for WP 3.4

First I'd like to say that I like the plugin. However, I just came across to this post: http://gtranslate.net/blog/46-gtranslate-got-reviewed-on-killerstartups

Somebody is stating that this plugin violates the TOS of Google. I checked the code and is true, here I'm pasting the important parts of the messages:

http://www.google.com/intl/en/policies/terms/

"...don’t interfere with our Services or try to access them using a method other than the interface and the instructions that we provide..."

"...Don’t remove, obscure, or alter any legal notices displayed in or along with our Services..."

This is how the script obscures the user interface:

#goog-gt-tt {display:none !important;}
.goog-te-banner-frame {display:none !important;}
.goog-te-menu-value:hover {text-decoration:none !important;}
body {top:0 !important;}
#google_translate_element2 {display:none!important;}

Then there're a couple of js (packed) functions to fire the events on the original (and now hidden) user interface.

And the requests go directly to Google's server. And the script is loading the Google's translation widget: http://translate.google.com/translate_a/element.js?cb=googleTranslateElementInit2

You said that you're using the Google Translation API. Is a paid service (https://developers.google.com/translate/v2/pricing), that's why it brought my attention. So, unless I'm missing something really really big, what you've said is not true, at least for the free version of the script. I cannot say anything about the paid versions because I haven't seen them, but I have to admit that I'm afraid that they'll do something similar.

---

I'm posting this here to prevent internet lawsuits to simple people. And honestly, I don't understand how come such plugin is available for download here, as it can cause a lot of damage. Who knows what Google might do when they find out.

You must log in to submit a review. You can also log in or register using the form near the top of this page.