Google XML News Sitemap plugin Security & Risk Analysis

wordpress.org/plugins/gn-xml-sitemap

This is a Beta release. If you find a bug or you have a feature request, feel free to mail the developer.

60 active installs v0.02 PHP + WP 2.5+ Updated Mar 11, 2010
googlegoogle-newsnewspostseo
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEAug 25, 2025
Safety Verdict

Is Google XML News Sitemap plugin Safe to Use in 2026?

Use With Caution

Score 63/100

Google XML News Sitemap plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Aug 25, 2025Updated 16yr ago
Risk Assessment

The gn-xml-sitemap plugin exhibits a mixed security posture. While the static analysis reveals a very small attack surface with no identified direct entry points, several concerning signals emerge from the code analysis and vulnerability history. The high percentage of unsanitized output (91%) is a significant concern, indicating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is ever incorporated into outputs. Furthermore, the single SQL query is not using prepared statements, which presents a risk of SQL injection, albeit with only one query present.

The plugin's vulnerability history shows a single medium-severity CVE, specifically a Cross-Site Request Forgery (CSRF), which has not been patched. This indicates a past weakness and a present ongoing risk. The fact that the only known vulnerability was CSRF, and that it remains unpatched, coupled with the high rate of unescaped output, suggests that the plugin developers may not be prioritizing robust input validation and output sanitization, or may have a tendency to overlook certain security best practices. While the absence of critical taint flows and a large attack surface is positive, the unpatched medium vulnerability and the alarming output escaping statistics necessitate careful consideration.

Key Concerns

  • Unpatched medium severity CVE
  • High percentage of unescaped output
  • SQL query without prepared statements
Vulnerabilities
1

Google XML News Sitemap plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-48304medium · 6.1Cross-Site Request Forgery (CSRF)

Google XML News Sitemap plugin <= 0.02 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Aug 25, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Google XML News Sitemap plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
10
1 escaped
Nonce Checks
1
Capability Checks
2
File Operations
5
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

9% escaped11 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
gns_admin_page (main.php:526)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Google XML News Sitemap plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actiondelete_postmain.php:37
actionpublish_postmain.php:38
actionpublish_postmain.php:39
actionsave_postmain.php:40
actionadmin_menumain.php:48
actionadmin_menumain.php:49
actiondbx_post_advancedmain.php:383
Maintenance & Trust

Google XML News Sitemap plugin Maintenance & Trust

Maintenance Signals

WordPress version tested2.9.2
Last updatedMar 11, 2010
PHP min version
Downloads15K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Google XML News Sitemap plugin Developer Profile

Gary Illyes

1 plugin · 60 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Google XML News Sitemap plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gn-xml-sitemap/main.php

HTML / DOM Fingerprints

Data Attributes
name="gns_notnews"name="gns_n_lang"name="gns_n_genres_type"name="gns_n_access_type"name="gns_kywrds"name="gns_stock"
FAQ

Frequently Asked Questions about Google XML News Sitemap plugin