
APG Google Image Sitemap Feed Security & Risk Analysis
wordpress.org/plugins/google-image-sitemap-feed-with-multisite-supportGenera dinámicamente el archivo sitemap-image.xml, un mapa de sitio de imágenes para Google. No requiere ningún tipo de configuración.
Is APG Google Image Sitemap Feed Safe to Use in 2026?
Generally Safe
Score 85/100APG Google Image Sitemap Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'google-image-sitemap-feed-with-multisite-support' plugin version 2.0.2.2 exhibits a mixed security posture. On the positive side, there are no recorded CVEs, no dangerous functions identified, and a minimal attack surface with no apparent unprotected entry points. This suggests a commitment to basic security hygiene.
However, the static analysis reveals significant concerns. The plugin makes external HTTP requests which could be vectors for SSRF or data exfiltration if not handled carefully. More critically, 100% of its single SQL query is not using prepared statements, a substantial risk for SQL injection. Furthermore, 100% of its output escaping is missing, opening the door to Cross-Site Scripting (XSS) vulnerabilities, particularly given the absence of any capability checks. The single taint flow with unsanitized paths, although not rated critical or high, warrants attention. The lack of nonce and capability checks, combined with unescaped output, creates a dangerous combination where malicious input could be processed and reflected without proper validation.
In conclusion, while the plugin benefits from a lack of known vulnerabilities and a small attack surface, the identified coding practices around SQL, output escaping, and lack of authorization checks represent substantial weaknesses that could be exploited. The absence of these fundamental security measures is concerning and requires immediate attention.
Key Concerns
- 100% SQL queries without prepared statements
- 100% outputs not properly escaped
- No capability checks
- Flow with unsanitized paths detected
- No nonce checks
- External HTTP requests made
APG Google Image Sitemap Feed Security Vulnerabilities
APG Google Image Sitemap Feed Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
APG Google Image Sitemap Feed Attack Surface
WordPress Hooks 13
Scheduled Events 1
Maintenance & Trust
APG Google Image Sitemap Feed Maintenance & Trust
Maintenance Signals
Community Trust
APG Google Image Sitemap Feed Alternatives
Complete Image Sitemap
complete-image-sitemap
The Complete Image Sitemap plugin will generate an XML Sitemap for all images, including Woocommerce products.
Simple Image XML Sitemap
simple-image-xml-sitemap
The Simple Image XML Sitemap plugin will generate a XML Sitemap for specifically for all images including images uploaded as Advanced Custom Fields (P …
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
SureRank SEO – Smart Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
surerank
SureRank – SEO Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
SEOPress – On-site SEO & Analytics
wp-seopress
SEOPress, a simple, fast and powerful all in one SEO plugin for WordPress. Rank higher in search engines, fully white label. Now with AI.
APG Google Image Sitemap Feed Developer Profile
9 plugins · 19K total installs
How We Detect APG Google Image Sitemap Feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/google-image-sitemap-feed-with-multisite-support/assets/fonts/stylesheet.cssHTML / DOM Fingerprints
artprojectgroupgenericongenericon-cartgenericon-facebook-altgenericon-linkedingenericon-mailgenericon-skypegenericon-twitter+2 moretitletargethref