
LMC XML Reader Security & Risk Analysis
wordpress.org/plugins/lmc-xml-readerLMC XML Reader plugin can load, parse and display an external XML file from given URL (LMC.cz, Jobs.cz, Prace.cz, Teamio.com).
Is LMC XML Reader Safe to Use in 2026?
Generally Safe
Score 85/100LMC XML Reader has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'lmc-xml-reader' v1.1 plugin presents a mixed security posture. On the positive side, it exhibits no known historical vulnerabilities (CVEs) and its static analysis reveals no dangerous functions, no raw SQL queries, and no file operations. The absence of critical or high-severity taint flows is also reassuring. However, significant concerns arise from the code analysis. The complete lack of output escaping (0% properly escaped) on 35 outputs is a critical weakness, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) attacks. Furthermore, the absence of nonce checks and capability checks on its single shortcode entry point means that any authenticated user could potentially trigger unintended actions through this shortcode. The single external HTTP request also warrants scrutiny, though without further context, its risk is indeterminate. The plugin's lack of historical vulnerabilities might indicate either a very low-risk plugin or simply a lack of in-depth security auditing. Coupled with the identified output escaping and authorization weaknesses, the plugin, despite its clean history, carries a substantial risk.
Key Concerns
- All outputs are unescaped
- Shortcode lacks nonce checks
- Shortcode lacks capability checks
LMC XML Reader Security Vulnerabilities
LMC XML Reader Code Analysis
Output Escaping
LMC XML Reader Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
LMC XML Reader Maintenance & Trust
Maintenance Signals
Community Trust
LMC XML Reader Alternatives
BeerXML Shortcode
beerxml-shortcode
Automatically insert and display beer recipes by linking to a BeerXML document.
Ten&Two XSLT Processor
tenandtwo-xslt-processor
Transform and display XML from local and remote sources using PHP's XSL extension.
XS2H XML Sitemap to HTML
xs2h-xml-sitemap-to-html
Generate a searchable HTML list or table from one or more XML sitemaps via a simple shortcode.
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
LMC XML Reader Developer Profile
2 plugins · 20 total installs
How We Detect LMC XML Reader
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lmc-xml-reader/lmc-xml-reader.phpHTML / DOM Fingerprints
lmc-datelmc-divlmc-showlmc-hidden-limitlmc-desclmc-itemlmc-noresultslmc-show+1 moredata-relateddata-companydata-locationrelatedpositionscounterregion<option value="<div class="lmc-div<div class="lmc-item<a href="