APG Google Video Sitemap Feed Security & Risk Analysis

wordpress.org/plugins/google-video-sitemap-feed-with-multisite-support

Genera dinámicamente el archivo sitemap-video.xml, un mapa de sitio de vídeos para Google. No requiere ningún tipo de configuración.

800 active installs v2.1 PHP + WP 2.6+ Updated Feb 15, 2023
googlegoogle-videogoogle-video-sitemapsitemap-videovideo-sitemap
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is APG Google Video Sitemap Feed Safe to Use in 2026?

Generally Safe

Score 85/100

APG Google Video Sitemap Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin "google-video-sitemap-feed-with-multisite-support" v2.1 exhibits a mixed security posture. On one hand, the static analysis reveals no apparent direct entry points like AJAX handlers, REST API routes, or shortcodes that are unprotected. Additionally, there are no known critical or high-severity vulnerabilities in its history, suggesting a generally stable and well-maintained codebase.

However, significant concerns arise from the lack of secure coding practices. The analysis shows 100% of SQL queries are not using prepared statements, which is a major risk for SQL injection vulnerabilities. Furthermore, a concerning 100% of output is not properly escaped, opening the door to cross-site scripting (XSS) attacks. The absence of nonce checks and capability checks on any potential backend operations is another critical oversight. The presence of external HTTP requests, while not inherently problematic, warrants attention as they can be vectors for further attacks if not handled with proper validation and sanitization.

While the plugin's vulnerability history is clean, the extensive use of insecure coding patterns like unescaped output and raw SQL queries presents a substantial inherent risk. These are fundamental security flaws that could be easily exploited. The plugin's strengths lie in its limited attack surface and clean vulnerability record, but these are overshadowed by critical weaknesses in data handling and user input validation.

Key Concerns

  • SQL queries without prepared statements
  • Unescaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

APG Google Video Sitemap Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

APG Google Video Sitemap Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
22
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

0% escaped22 total outputs
Attack Surface

APG Google Video Sitemap Feed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionadmin_initapg-xml-sitemap.php:36
actionadmin_menuapg-xml-sitemap.php:42
filteraction_scheduler_retention_periodapg-xml-sitemap.php:53
actionapg_video_sitemap_procesamientoapg-xml-sitemap.php:61
actionupgrader_process_completeapg-xml-sitemap.php:79
actioninitincludes\admin\clases\xml.php:10
actiondo_feed_sitemap-videoincludes\admin\clases\xml.php:11
filtergenerate_rewrite_rulesincludes\admin\clases\xml.php:12
actionenviar_pingincludes\admin\clases\xml.php:13
actionpublish_postincludes\admin\clases\xml.php:15
actionpublish_pageincludes\admin\clases\xml.php:16
actiondelete_postincludes\admin\clases\xml.php:17
actionpre_post_updateincludes\admin\clases\xml.php:18
filterxml_sitemap_urlincludes\admin\clases\xml.php:24
actionplugins_loadedincludes\admin\funciones-apg.php:20
filterplugin_row_metaincludes\admin\funciones-apg.php:38
actionadmin_enqueue_scriptsincludes\admin\funciones-apg.php:92

Scheduled Events 1

enviar_ping
Maintenance & Trust

APG Google Video Sitemap Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedFeb 15, 2023
PHP min version
Downloads48K

Community Trust

Rating56/100
Number of ratings9
Active installs800
Developer Profile

APG Google Video Sitemap Feed Developer Profile

Art Project Group

9 plugins · 19K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
258 days
View full developer profile
Detection Fingerprints

How We Detect APG Google Video Sitemap Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
/wp-content/plugins/google-video-sitemap-feed-with-multisite-support/css/style.css?ver=/wp-content/plugins/google-video-sitemap-feed-with-multisite-support/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
apg-video-sitemap-settings
HTML Comments
<!-- APG Google Video Sitemap Feed Options --><!-- APG Settings Form -->
Data Attributes
data-apg-video-sitemap-nonce
JS Globals
apg_video_sitemap_options
FAQ

Frequently Asked Questions about APG Google Video Sitemap Feed