APG Google Image Sitemap Feed Security & Risk Analysis

wordpress.org/plugins/google-image-sitemap-feed-with-multisite-support

Genera dinámicamente el archivo sitemap-image.xml, un mapa de sitio de imágenes para Google. No requiere ningún tipo de configuración.

1K active installs v2.0.2.2 PHP + WP 2.6+ Updated Jun 25, 2022
googlegoogle-imagegoogle-image-sitemapsitemapsitemap-image-xml
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is APG Google Image Sitemap Feed Safe to Use in 2026?

Generally Safe

Score 85/100

APG Google Image Sitemap Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'google-image-sitemap-feed-with-multisite-support' plugin version 2.0.2.2 exhibits a mixed security posture. On the positive side, there are no recorded CVEs, no dangerous functions identified, and a minimal attack surface with no apparent unprotected entry points. This suggests a commitment to basic security hygiene.

However, the static analysis reveals significant concerns. The plugin makes external HTTP requests which could be vectors for SSRF or data exfiltration if not handled carefully. More critically, 100% of its single SQL query is not using prepared statements, a substantial risk for SQL injection. Furthermore, 100% of its output escaping is missing, opening the door to Cross-Site Scripting (XSS) vulnerabilities, particularly given the absence of any capability checks. The single taint flow with unsanitized paths, although not rated critical or high, warrants attention. The lack of nonce and capability checks, combined with unescaped output, creates a dangerous combination where malicious input could be processed and reflected without proper validation.

In conclusion, while the plugin benefits from a lack of known vulnerabilities and a small attack surface, the identified coding practices around SQL, output escaping, and lack of authorization checks represent substantial weaknesses that could be exploited. The absence of these fundamental security measures is concerning and requires immediate attention.

Key Concerns

  • 100% SQL queries without prepared statements
  • 100% outputs not properly escaped
  • No capability checks
  • Flow with unsanitized paths detected
  • No nonce checks
  • External HTTP requests made
Vulnerabilities
None known

APG Google Image Sitemap Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

APG Google Image Sitemap Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

0% escaped7 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<contenido-xml> (includes\admin\clases\contenido-xml.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

APG Google Image Sitemap Feed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionupgrader_process_completeapg-xml-sitemap.php:48
actioninitincludes\admin\clases\xml.php:10
actiondo_feed_sitemap-imageincludes\admin\clases\xml.php:11
filtergenerate_rewrite_rulesincludes\admin\clases\xml.php:12
actionenviar_pingincludes\admin\clases\xml.php:13
actionpublish_postincludes\admin\clases\xml.php:15
actionpublish_pageincludes\admin\clases\xml.php:16
actiondelete_postincludes\admin\clases\xml.php:17
actionpre_post_updateincludes\admin\clases\xml.php:18
filterxml_sitemap_urlincludes\admin\clases\xml.php:24
actionplugins_loadedincludes\admin\funciones-apg.php:20
filterplugin_row_metaincludes\admin\funciones-apg.php:38
actionadmin_enqueue_scriptsincludes\admin\funciones-apg.php:75

Scheduled Events 1

enviar_ping
Maintenance & Trust

APG Google Image Sitemap Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJun 25, 2022
PHP min version
Downloads46K

Community Trust

Rating72/100
Number of ratings5
Active installs1K
Developer Profile

APG Google Image Sitemap Feed Developer Profile

Art Project Group

9 plugins · 19K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
258 days
View full developer profile
Detection Fingerprints

How We Detect APG Google Image Sitemap Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/google-image-sitemap-feed-with-multisite-support/assets/fonts/stylesheet.css

HTML / DOM Fingerprints

CSS Classes
artprojectgroupgenericongenericon-cartgenericon-facebook-altgenericon-linkedingenericon-mailgenericon-skypegenericon-twitter+2 more
Data Attributes
titletargethref
FAQ

Frequently Asked Questions about APG Google Image Sitemap Feed