Lightweight Sitemap Generator Security & Risk Analysis

wordpress.org/plugins/lightweight-sitemap-generator

XML sitemap generator for WordPress with file or dynamic mode. Supports all public post types and taxonomies. Optional Google News sitemap.

80 active installs v1.0.21 PHP 7.0+ WP 4.8+ Updated Mar 13, 2026
googlesite-mapsitemapxml-sitemapyandex
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Lightweight Sitemap Generator Safe to Use in 2026?

Generally Safe

Score 100/100

Lightweight Sitemap Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21d ago
Risk Assessment

The 'lightweight-sitemap-generator' plugin version 1.0.21 demonstrates a generally strong security posture, with no known vulnerabilities or CVEs recorded. The static analysis reveals no direct attack surface through AJAX, REST API, shortcodes, or cron events, indicating a well-defined and contained functionality. The code also shows good practices in terms of dangerous functions, external HTTP requests, and a significant proportion of SQL queries using prepared statements. Furthermore, a good percentage of output is properly escaped, and nonce and capability checks are present.

However, there are a couple of areas that warrant attention. The taint analysis shows two flows with unsanitized paths. While not classified as critical or high severity in this analysis, unsanitized paths can often be precursors to path traversal vulnerabilities if not handled meticulously. The file operations, though not explicitly detailed as problematic, combined with unsanitized paths, represent a potential area for concern. The plugin's vulnerability history, being entirely clean, is a significant positive, suggesting diligent development and maintenance.

In conclusion, the plugin appears to be developed with security in mind, exhibiting a low risk profile. The absence of known vulnerabilities is a strong indicator of its robustness. The primary area for improvement lies in ensuring the complete sanitization of all path-related inputs, even if the current analysis did not flag them as critical. The presence of file operations and unsanitized paths, while not leading to immediate critical flaws in this assessment, should be monitored and addressed to maintain this strong security record.

Key Concerns

  • Flows with unsanitized paths found
Vulnerabilities
None known

Lightweight Sitemap Generator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Lightweight Sitemap Generator Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
4 prepared
Unescaped Output
66
301 escaped
Nonce Checks
6
Capability Checks
11
File Operations
10
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared6 total queries

Output Escaping

82% escaped367 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
maybe_serve_sitemap (includes\class-lwsgp-sitemap-generator.php:4968)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Lightweight Sitemap Generator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
filterplugin_localeincludes\class-lwsgp-sitemap-generator.php:45
actionplugins_loadedincludes\class-lwsgp-sitemap-generator.php:46
filterquery_varsincludes\class-lwsgp-sitemap-generator.php:47
actioninitincludes\class-lwsgp-sitemap-generator.php:48
actiontemplate_redirectincludes\class-lwsgp-sitemap-generator.php:49
actionadmin_menuincludes\class-lwsgp-sitemap-generator.php:56
actionadmin_initincludes\class-lwsgp-sitemap-generator.php:57
actionadmin_enqueue_scriptsincludes\class-lwsgp-sitemap-generator.php:58
actionadmin_post_lwsgp_refresh_previewincludes\class-lwsgp-sitemap-generator.php:61
actionadmin_post_lwsgp_scan_ondiskincludes\class-lwsgp-sitemap-generator.php:62
actionsave_postincludes\class-lwsgp-sitemap-generator.php:68
actiondeleted_postincludes\class-lwsgp-sitemap-generator.php:69
actiontrashed_postincludes\class-lwsgp-sitemap-generator.php:70
actionset_object_termsincludes\class-lwsgp-sitemap-generator.php:71
actioncreated_termincludes\class-lwsgp-sitemap-generator.php:72
actionedited_termincludes\class-lwsgp-sitemap-generator.php:73
actiondelete_termincludes\class-lwsgp-sitemap-generator.php:74
filterredirect_canonicalincludes\class-lwsgp-sitemap-generator.php:79
filterwp_sitemaps_enabledincludes\class-lwsgp-sitemap-generator.php:81
filterpre_handle_404includes\class-lwsgp-sitemap-generator.php:82
filteroverride_load_textdomainincludes\class-lwsgp-sitemap-generator.php:6536
Maintenance & Trust

Lightweight Sitemap Generator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

Lightweight Sitemap Generator Developer Profile

andreyberestov

1 plugin · 80 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lightweight Sitemap Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lightweight-sitemap-generator/assets/css/admin.css
Version Parameters
lwsgp-admin

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Lightweight Sitemap Generator