
Easy HTML Sitemap Security & Risk Analysis
wordpress.org/plugins/easy-html-sitemapEasy HTML Sitemap - Display an HTML Sitemap for your wordpress pages using a shortcode. The sitemap is updated in realtime.
Is Easy HTML Sitemap Safe to Use in 2026?
Generally Safe
Score 85/100Easy HTML Sitemap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "easy-html-sitemap" v1.4.9 plugin exhibits a generally positive security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries use prepared statements exclusively, and there are no file operations or external HTTP requests. The absence of known CVEs and a clean vulnerability history further bolster confidence in its security. However, there are areas for improvement. The plugin has a low overall attack surface with only one shortcode, and importantly, all entry points appear to be protected by default. The primary concern is the output escaping, which is only properly handled in 59% of cases. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. While taint analysis found no issues, the unescaped output is a significant enough concern to warrant attention.
In conclusion, the plugin demonstrates good development practices by avoiding common pitfalls like raw SQL and dangerous functions. Its vulnerability history is excellent. The main weakness lies in the insufficient output escaping, which, despite the lack of identified taint flows in this analysis, remains a potential entry point for attacks. The absence of nonce and capability checks on its single entry point (the shortcode) suggests a reliance on WordPress's default security mechanisms, which might not always be sufficient depending on how the shortcode is implemented and used.
Key Concerns
- Insufficient output escaping (59% properly escaped)
- No capability checks on entry points
- No nonce checks on entry points
Easy HTML Sitemap Security Vulnerabilities
Easy HTML Sitemap Code Analysis
Output Escaping
Easy HTML Sitemap Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Easy HTML Sitemap Maintenance & Trust
Maintenance Signals
Community Trust
Easy HTML Sitemap Alternatives
WP Sitemap Page
wp-sitemap-page
Add a sitemap on any of your page using the simple shortcode [wp_sitemap_page]. Improve the SEO and navigation of your website.
WP Sitemap Pages and Posts
wp-sitemap-pages-and-posts
An easy way to add a sitemap on one of your pages becomes reality thanks to this WordPress plugin. Just use the shortcode [wpspap_sitemap] on any of y …
Page-list
page-list
[pagelist], [subpages], [siblings] and [pagelist_ext] shortcodes
Simple Hierarchical Sitemap
simple-hierarchical-sitemap
Simple Hierarchical Sitemap is the simple way to add an HTML sitemap to your wordpress blog...
Custom Sitemap Shortcode
custom-sitemap-template
Plugin provides a sitemap shortcode. You can use shortcode on any page to display sitemap. You can fully customize your sitemap using plugin settings.
Easy HTML Sitemap Developer Profile
6 plugins · 21K total installs
How We Detect Easy HTML Sitemap
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-html-sitemap/css/wff-admin.css/wp-content/plugins/easy-html-sitemap/js/my-custom.js/wp-content/plugins/easy-html-sitemap/js/my-custom.jseasy-html-sitemap/css/wff-admin.css?ver=easy-html-sitemap/js/my-custom.js?ver=HTML / DOM Fingerprints
easy-html-sitemapeasy-html-sitemap__itemeasy-html-sitemap__item-titleeasy-html-sitemap__listpost-type-pagethis is closing div of sitemap wrapperdata-easy-html-sitemap-excludedata-easy-html-sitemap-order-bydata-easy-html-sitemap-orderdata-easy-html-sitemap-limit-itemdata-easy-html-sitemap-open-new-tabdata-easy-html-sitemap-title-tag+2 morewbehs_custom_wp_admin_js<div class="easy-html-sitemap">