
Companion Sitemap Generator – HTML & XML Security & Risk Analysis
wordpress.org/plugins/companion-sitemap-generatorEasy to use XML and HTML sitemap generator + Robots editor
Is Companion Sitemap Generator – HTML & XML Safe to Use in 2026?
Generally Safe
Score 98/100Companion Sitemap Generator – HTML & XML has a strong security track record. Known vulnerabilities have been patched promptly.
The companion-sitemap-generator plugin version 4.5.9.3 exhibits a mixed security posture. While it demonstrates good practices in using prepared statements for the vast majority of its SQL queries and includes a reasonable number of nonce and capability checks, significant concerns arise from its output escaping and past vulnerability history. The fact that only 35% of output is properly escaped suggests a strong potential for Cross-Site Scripting (XSS) vulnerabilities, which aligns with past CVE types. Furthermore, the presence of one unsanitized path flow in the taint analysis, even without a critical or high severity rating, warrants attention as it indicates a potential vector for path traversal or other file-related exploits. The plugin has a history of 3 known CVEs, with one high and two medium severity vulnerabilities, all of which are now patched. However, the recurrence of XSS and CSRF in its vulnerability history, coupled with the low output escaping rate, highlights a persistent weakness in handling user-supplied data securely.
In conclusion, while the plugin is actively maintained and previous vulnerabilities have been patched, the low rate of proper output escaping and the identified unsanitized path flow are considerable risks. The historical pattern of XSS and CSRF vulnerabilities also suggests a need for more robust input validation and output sanitization. This plugin has strengths in its SQL handling and authentication checks, but these are overshadowed by the potential for client-side and potentially file-system related vulnerabilities. Vigilance and thorough auditing of output handling mechanisms are recommended.
Key Concerns
- Low percentage of properly escaped output
- Unsanitized path flow identified
- History of High severity CVE
- History of Medium severity CVEs
Companion Sitemap Generator – HTML & XML Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Companion Sitemap Generator <= 4.5.1.1 - Reflected Cross-Site Scripting
Companion Sitemap Generator <= 4.5.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Companion Sitemap Generator – HTML & XML <= 3.6.6 - Cross-Site Request Forgery and Local File Inclusion
Companion Sitemap Generator – HTML & XML Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Companion Sitemap Generator – HTML & XML Attack Surface
Shortcodes 1
WordPress Hooks 12
Scheduled Events 2
Maintenance & Trust
Companion Sitemap Generator – HTML & XML Maintenance & Trust
Maintenance Signals
Community Trust
Companion Sitemap Generator – HTML & XML Alternatives
Polylang Dynamic Sitemap Generator
polylang-dynamic-sitemap-generator
Polylang Dynamic Sitemap Generator is a powerful WordPress plugin that automatically generates SEO-friendly sitemaps for all active languages and post …
Advanced SEO Toolkit
advanced-seo-toolkit
Advanced SEO Toolkit is a comprehensive solution for optimizing your WordPress site for search engines.
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
XML Sitemap Generator for Google
google-sitemap-generator
Generate multiple types of sitemaps to improve SEO and get your website indexed quickly.
Companion Sitemap Generator – HTML & XML Developer Profile
3 plugins · 60K total installs
How We Detect Companion Sitemap Generator – HTML & XML
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/companion-sitemap-generator/frontend/style.csscompanion-sitemap-generator/frontend/style.css?ver=HTML / DOM Fingerprints
No script kiddies please!