Image & Video XML Sitemap Security & Risk Analysis

wordpress.org/plugins/image-video-xml-sitemap

Create separate XML sitemaps for images and videos with advanced customization. Fully compatible with Yoast SEO.

300 active installs v1.0.8 PHP 7.4+ WP 5.2+ Updated Dec 5, 2025
image-sitemapseositemapsvideo-sitemapxml-sitemap
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Image & Video XML Sitemap Safe to Use in 2026?

Generally Safe

Score 100/100

Image & Video XML Sitemap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "image-video-xml-sitemap" plugin v1.0.9 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant positive. Furthermore, the code signals indicate good development practices with 100% of SQL queries utilizing prepared statements and a high percentage (84%) of output being properly escaped. The presence of nonce and capability checks, albeit limited, further bolsters its security. The taint analysis revealing no unsanitized paths or critical/high severity flows is also reassuring.

The plugin's vulnerability history is also empty, with no known CVEs or recorded past vulnerabilities. This suggests a history of stable and secure development. However, it's important to note that the attack surface, while currently zero for unprotected points, might expand with future features. The limited number of capability checks and nonce checks, while present, could be expanded to cover more interactions if the plugin evolves to have more dynamic features or user interactions.

In conclusion, the "image-video-xml-sitemap" plugin v1.0.9 appears to be very secure. Its minimal attack surface, adherence to secure coding practices like prepared statements and output escaping, and a clean vulnerability history are all strong indicators of a robust security implementation. The only minor areas for potential enhancement would be if the plugin were to introduce more complex features in the future, requiring a commensurate increase in protective measures like nonce and capability checks.

Vulnerabilities
None known

Image & Video XML Sitemap Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Image & Video XML Sitemap Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
26 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

84% escaped31 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ivxs_save_settings (includes\class-image-video-xml-sitemap.php:172)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Image & Video XML Sitemap Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionplugins_loadedimage-video-xml-sitemap.php:32
actionadmin_initimage-video-xml-sitemap.php:46
actionadmin_noticesimage-video-xml-sitemap.php:50
actionadmin_noticesimage-video-xml-sitemap.php:53
actionadmin_menuincludes\class-image-video-xml-sitemap.php:9
actionadmin_enqueue_scriptsincludes\class-image-video-xml-sitemap.php:10
actionadmin_post_save_ivxs_settingsincludes\class-image-video-xml-sitemap.php:11
actionwpseo_sitemap_indexincludes\class-image-video-xml-sitemap.php:12
actioninitincludes\class-image-video-xml-sitemap.php:13
filterquery_varsincludes\class-image-video-xml-sitemap.php:14
actiontemplate_redirectincludes\class-image-video-xml-sitemap.php:15
filterredirect_canonicalincludes\class-image-video-xml-sitemap.php:16
Maintenance & Trust

Image & Video XML Sitemap Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 5, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs300
Developer Profile

Image & Video XML Sitemap Developer Profile

Harpalsinh Parmar

4 plugins · 350 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image & Video XML Sitemap

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-video-xml-sitemap/assets/css/ivxs-admin-css.css/wp-content/plugins/image-video-xml-sitemap/assets/js/ivxs-admin-js.js
Script Paths
/wp-content/plugins/image-video-xml-sitemap/assets/js/ivxs-admin-js.js
Version Parameters
ivxs-admin-css.css?ver=ivxs-admin-js.js?ver=

HTML / DOM Fingerprints

CSS Classes
ivxs-titleivxs-rowivxs-col-8ivxs-d-flexivxs-global-options
Data Attributes
for="image-sitemap-toggle"name="ivxs_enable_image_sitemap"id="image-sitemap-toggle"name="ivxs_image_sitemap_filename"id="image-sitemap-filename"
JS Globals
ivxs_ajax_obj
Shortcode Output
<?php esc_html_e( 'Image & Video XML Sitemap', 'image-video-xml-sitemap' ); ?>
FAQ

Frequently Asked Questions about Image & Video XML Sitemap