
Sitemap Generator Professional Security & Risk Analysis
wordpress.org/plugins/mb-sitemap-generatorAn easy to use XML sitemap generator with support for image and video sitemaps for WordPress.
Is Sitemap Generator Professional Safe to Use in 2026?
Generally Safe
Score 85/100Sitemap Generator Professional has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mb-sitemap-generator plugin, version 1.7.7, presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has no recorded vulnerabilities (CVEs) or taint analysis findings, indicating a generally stable codebase. The absence of bundled libraries is also a good sign, as it avoids potential issues with outdated or vulnerable third-party code.
However, significant security concerns are present in the attack surface. The plugin exposes one AJAX handler that lacks authentication checks. This is a critical oversight, as it allows any unauthenticated user to potentially interact with this handler, opening the door to various attacks if the handler performs sensitive actions or processes user-supplied data without proper validation. Furthermore, the code exhibits a concerning rate of unescaped output, with only 39% of outputs properly escaped. This significantly increases the risk of cross-site scripting (XSS) vulnerabilities, where attackers could inject malicious scripts into the site's content.
While the lack of historical vulnerabilities is a positive indicator, it does not negate the immediate risks posed by the unauthenticated AJAX handler and widespread output escaping issues. The plugin's strengths in SQL handling and absence of critical taint flows are overshadowed by these critical weaknesses. Therefore, while the plugin has a relatively clean history, the current version's unauthenticated entry points and output escaping deficiencies warrant immediate attention.
Key Concerns
- Unauthenticated AJAX handler
- Low percentage of properly escaped output
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
Sitemap Generator Professional Security Vulnerabilities
Sitemap Generator Professional Code Analysis
Output Escaping
Sitemap Generator Professional Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Sitemap Generator Professional Maintenance & Trust
Maintenance Signals
Community Trust
Sitemap Generator Professional Alternatives
Image & Video XML Sitemap
image-video-xml-sitemap
Create separate XML sitemaps for images and videos with advanced customization. Fully compatible with Yoast SEO.
XML Sitemap Generator for Google
google-sitemap-generator
Generate multiple types of sitemaps to improve SEO and get your website indexed quickly.
Dynamic XML Sitemaps Generator for Google
xml-sitemap-generator-for-google
Boost SEO 🚀 with powerful XML, HTML, Image, Video & Google News sitemaps for better search engine indexing.
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
Sitemap Generator Professional Developer Profile
2 plugins · 8K total installs
How We Detect Sitemap Generator Professional
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mb-sitemap-generator/css/wrapped.min.css/wp-content/plugins/mb-sitemap-generator/css/custom.css/wp-content/plugins/mb-sitemap-generator/js/sitemap-generator-1.1.1.min.jsmb-sitemap-generator/js/sitemap-generator-1.1.1.min.js?v=mb-sitemap-generator/css/wrapped.min.css?v=mb-sitemap-generator/css/custom.css?v=HTML / DOM Fingerprints
bootstrap3sitemap-generatorproxy-urlwebsite-urlsitemap-filenametokensystem-name+9 moreriot/wp-json/sitemap_proxy