Google News Sitemap Feed With Multisite Support Security & Risk Analysis

wordpress.org/plugins/google-news-sitemap-feed-with-multisite-support

Dynamically generates a Google News Sitemap. Multisite compatible.

100 active installs v3.3 PHP + WP 2.6+ Updated Jan 26, 2011
googlegoogle-newsgoogle-news-sitemapnews-sitemapsitemap
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Google News Sitemap Feed With Multisite Support Safe to Use in 2026?

Generally Safe

Score 85/100

Google News Sitemap Feed With Multisite Support has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The 'google-news-sitemap-feed-with-multisite-support' plugin v3.3 exhibits a mixed security posture. On the positive side, the static analysis shows a remarkably clean attack surface with zero identified AJAX handlers, REST API routes, shortcodes, or cron events, all of which are often common entry points for exploits. Furthermore, there are no dangerous functions, file operations, or external HTTP requests detected, and importantly, no known historical vulnerabilities or CVEs associated with this plugin. This suggests a diligent approach to minimizing potential exploit vectors and a history of stable, secure development.

However, significant concerns arise from the code signals. The plugin performs 18 SQL queries, none of which utilize prepared statements. This represents a substantial risk of SQL injection vulnerabilities, especially considering the lack of capability checks and nonce checks across any potential entry points. Additionally, only 29% of output is properly escaped, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis did not reveal immediate critical or high-severity flows, the prevalence of raw SQL and insufficient output escaping creates a fertile ground for such issues to be discovered or exploited.

In conclusion, while the plugin's minimal attack surface and clean vulnerability history are commendable, the absence of prepared statements in all SQL queries and the low rate of output escaping are critical weaknesses that significantly elevate the risk profile. The developer has clearly focused on limiting entry points, but has overlooked fundamental security practices for data handling and output rendering, leaving the plugin susceptible to common web vulnerabilities.

Key Concerns

  • All SQL queries use raw SQL, no prepared statements
  • Low percentage of output properly escaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Google News Sitemap Feed With Multisite Support Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Google News Sitemap Feed With Multisite Support Code Analysis

Dangerous Functions
0
Raw SQL Queries
18
0 prepared
Unescaped Output
5
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared18 total queries

Output Escaping

29% escaped7 total outputs
Attack Surface

Google News Sitemap Feed With Multisite Support Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterposts_wherefeed-sitemap-news.php:47
filterpost_limitsfeed-sitemap-news.php:48
actioninitXMLSitemapFeed.class.php:15
actiondo_feed_sitemap-newsXMLSitemapFeed.class.php:18
filtergenerate_rewrite_rulesXMLSitemapFeed.class.php:21
filterxml_sitemap_urlXMLSitemapFeed.class.php:104
filterxml_sitemap_urlXMLSitemapFeed.class.php:108
Maintenance & Trust

Google News Sitemap Feed With Multisite Support Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedJan 26, 2011
PHP min version
Downloads34K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Google News Sitemap Feed With Multisite Support Developer Profile

timbrd

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Google News Sitemap Feed With Multisite Support

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/google-news-sitemap-feed-with-multisite-support/google-news-sitemap-feed.css/wp-content/plugins/google-news-sitemap-feed-with-multisite-support/google-news-sitemap-feed.js
Version Parameters
google-news-sitemap-feed-with-multisite-support/google-news-sitemap-feed.css?ver=google-news-sitemap-feed-with-multisite-support/google-news-sitemap-feed.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Copyright 2010 TimBrd (timbrd@gmail.com) --><!-- Copyright 2010 RavanH (http://4visions.nl/ email : ravanhagen@gmail.com) --><!-- AVAILABLE HOOKS --><!-- FILTERS -->+4 more
FAQ

Frequently Asked Questions about Google News Sitemap Feed With Multisite Support