EAS Sitemap Generator Security & Risk Analysis

wordpress.org/plugins/eas-sitemap-generator

Generate XML.

10 active installs v4.2 PHP + WP 3.0.1+ Updated Feb 12, 2017
eas-sitemap-generatorgooglepage-sitemappost-sitemapseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is EAS Sitemap Generator Safe to Use in 2026?

Generally Safe

Score 85/100

EAS Sitemap Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "eas-sitemap-generator" v4.2 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The complete absence of known CVEs and a low percentage of unpatched vulnerabilities indicate a history of responsible development and maintenance. The static analysis reveals no critical vulnerabilities such as unescaped output, dangerous functions, or raw SQL queries. However, the presence of two file operations without further context is a minor concern, and the 40% output escaping rate suggests a potential for minor cross-site scripting (XSS) vulnerabilities if the unescaped outputs are user-controllable. The lack of any entry points like AJAX handlers or REST API routes is a significant strength, drastically reducing the attack surface. The single capability check is also a positive sign of some access control. Overall, this plugin appears to be relatively secure, but the file operations and incomplete output escaping warrant cautious review.

Key Concerns

  • Incomplete output escaping
  • File operations present
Vulnerabilities
None known

EAS Sitemap Generator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

EAS Sitemap Generator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped5 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
eas_sitemap_options (eas-sitemap-generator.php:47)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

EAS Sitemap Generator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_enqueue_scriptseas-sitemap-generator.php:23
actioniniteas-sitemap-generator.php:25
actionwp_enqueue_scriptseas-sitemap-generator.php:33
actionadmin_menueas-sitemap-generator.php:40
Maintenance & Trust

EAS Sitemap Generator Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedFeb 12, 2017
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

EAS Sitemap Generator Developer Profile

jamilvelji

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EAS Sitemap Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eas-sitemap-generator/css/admin-eas-sitemap.css/wp-content/plugins/eas-sitemap-generator/css/eas-sitemap.css/wp-content/plugins/eas-sitemap-generator/js/eas-sitemap.js
Script Paths
/wp-content/plugins/eas-sitemap-generator/js/eas-sitemap.js
Version Parameters
eas-sitemap-generator/css/admin-eas-sitemap.css?ver=eas-sitemap-generator/css/eas-sitemap.css?ver=eas-sitemap-generator/js/eas-sitemap.js?ver=

HTML / DOM Fingerprints

CSS Classes
eas-post
Data Attributes
name="eas_inc_posted[]"
FAQ

Frequently Asked Questions about EAS Sitemap Generator