
Google XML News Sitemap plugin Security & Risk Analysis
wordpress.org/plugins/gn-xml-sitemapThis is a Beta release. If you find a bug or you have a feature request, feel free to mail the developer.
Is Google XML News Sitemap plugin Safe to Use in 2026?
Use With Caution
Score 63/100Google XML News Sitemap plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The gn-xml-sitemap plugin exhibits a mixed security posture. While the static analysis reveals a very small attack surface with no identified direct entry points, several concerning signals emerge from the code analysis and vulnerability history. The high percentage of unsanitized output (91%) is a significant concern, indicating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is ever incorporated into outputs. Furthermore, the single SQL query is not using prepared statements, which presents a risk of SQL injection, albeit with only one query present.
The plugin's vulnerability history shows a single medium-severity CVE, specifically a Cross-Site Request Forgery (CSRF), which has not been patched. This indicates a past weakness and a present ongoing risk. The fact that the only known vulnerability was CSRF, and that it remains unpatched, coupled with the high rate of unescaped output, suggests that the plugin developers may not be prioritizing robust input validation and output sanitization, or may have a tendency to overlook certain security best practices. While the absence of critical taint flows and a large attack surface is positive, the unpatched medium vulnerability and the alarming output escaping statistics necessitate careful consideration.
Key Concerns
- Unpatched medium severity CVE
- High percentage of unescaped output
- SQL query without prepared statements
Google XML News Sitemap plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Google XML News Sitemap plugin <= 0.02 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Google XML News Sitemap plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Google XML News Sitemap plugin Attack Surface
WordPress Hooks 7
Maintenance & Trust
Google XML News Sitemap plugin Maintenance & Trust
Maintenance Signals
Community Trust
Google XML News Sitemap plugin Alternatives
Sitemap Google News
sitemap-google-news
Automatically generates a Google News Sitemap using the Google News Sitemap specification.
XML News Sitemap Generator
free-news-sitemap-generator-by-kumarharshit-in
News Sitemap Generator - Automatically generate a Google News sitemap with zero configuration.
Lightweight Newscast XML Sitemap For Google News
lightweight-newscast-xml-sitemap-for-google-news
Generates a Google News compatible XML sitemap for WordPress sites to be submitted to Google Search Console for better news content indexing.
Meta News & Standout tag
meta-news-standout-tag
This tags are necessary if your blog or news website has been included to Google News.
XYZZY Basic SEO & Analytics
xyzzy-basic-seo-analytics
XYZZY Basic SEO & Analytics es un sencillo y ligero plugin con el que integrar Analytics y los metadatos SEO en nuestra web.
Google XML News Sitemap plugin Developer Profile
1 plugin · 60 total installs
How We Detect Google XML News Sitemap plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gn-xml-sitemap/main.phpHTML / DOM Fingerprints
name="gns_notnews"name="gns_n_lang"name="gns_n_genres_type"name="gns_n_access_type"name="gns_kywrds"name="gns_stock"