Robots & Sitemap Security & Risk Analysis

wordpress.org/plugins/robots-sitemap

Plugin allows easily generate sitemap.xml filе, create and edit robots.txt for your single site or multisite

400 active installs v1.3.0 PHP 5.6.4+ WP 5.0.0+ Updated Mar 16, 2021
indexingrobotsseositemapsitemap-by-type
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Robots & Sitemap Safe to Use in 2026?

Generally Safe

Score 85/100

Robots & Sitemap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The robots-sitemap plugin version 1.3.0 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for its SQL queries and has no recorded vulnerability history, including CVEs. This suggests a potentially mature and well-maintained codebase regarding external exploits and database interactions. However, significant concerns arise from the static analysis. The plugin exposes a total of 6 AJAX handlers, with 2 of them lacking proper authentication checks. This creates a direct attack vector for unauthorized actions to be performed on the WordPress site if these handlers are exploitable. Furthermore, only 38% of output is properly escaped, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities in the plugin's user-facing elements. While taint analysis shows no immediate critical or high-severity flows, the lack of authentication on AJAX endpoints and the poor output escaping are notable weaknesses that could be exploited.

Key Concerns

  • AJAX handlers without authentication checks
  • Low percentage of properly escaped output
Vulnerabilities
None known

Robots & Sitemap Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Robots & Sitemap Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
18 prepared
Unescaped Output
33
20 escaped
Nonce Checks
6
Capability Checks
0
File Operations
2
External Requests
1
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

100% prepared18 total queries

Output Escaping

38% escaped53 total outputs
Attack Surface
2 unprotected

Robots & Sitemap Attack Surface

Entry Points6
Unprotected2

AJAX Handlers 6

authwp_ajax_get_robotsadmin\class-admin.php:161
authwp_ajax_vo3da_save_sitemap_optionsadmin\class-admin.php:162
authwp_ajax_vo3da_clear_sitemap_cacheadmin\class-admin.php:163
authwp_ajax_vo3da_update_robotsadmin\class-admin.php:164
authwp_ajax_vo3da_replace_robotsadmin\class-admin.php:165
authwp_ajax_vo3da_sitemap_clear_cachefront\class-front.php:78
WordPress Hooks 28
actionadmin_enqueue_scriptsadmin\class-admin.php:128
actionadmin_enqueue_scriptsadmin\class-admin.php:129
actionadmin_initadmin\class-admin.php:134
actionadmin_menuadmin\class-admin.php:135
actionupdate_option_custom_sitemap_optionsadmin\class-admin.php:136
actionadd_meta_boxesadmin\class-admin.php:141
actionpost_updatedadmin\class-admin.php:142
actioncategory_edit_form_fieldsadmin\class-admin.php:147
actionpost_tag_edit_form_fieldsadmin\class-admin.php:148
actionedit_termadmin\class-admin.php:150
actiontransition_post_statusadmin\class-admin.php:155
actioncreated_termadmin\class-admin.php:156
actionplugins_loadedcore\class-i18n.php:38
actionwpfront\class-front.php:56
filterwp_sitemaps_enabledfront\class-front.php:62
actioncreated_termfront\class-front.php:64
actiondelete_termfront\class-front.php:65
actionedited_termfront\class-front.php:66
actionsave_postfront\class-front.php:68
actiondelete_postfront\class-front.php:69
actionwp_trash_postfront\class-front.php:70
actionedit_attachmentfront\class-front.php:72
actiondelete_attachmentfront\class-front.php:73
actionupdate_option_custom_sitemap_optionsfront\class-front.php:75
actionupdate_option_seo_ultimate_module_metafront\class-front.php:76
filtersitemap_date_formatfront\class-front.php:79
actionwpfront\class-front.php:88
filterrobots_txtfront\class-front.php:89
Maintenance & Trust

Robots & Sitemap Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedMar 16, 2021
PHP min version5.6.4
Downloads6K

Community Trust

Rating100/100
Number of ratings3
Active installs400
Developer Profile

Robots & Sitemap Developer Profile

Vo3da team

2 plugins · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Robots & Sitemap

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/robots-sitemap/assets/css/sitemap-robots.min.css/wp-content/plugins/robots-sitemap/assets/css/jquery.dataTables.min.css/wp-content/plugins/robots-sitemap/assets/js/sitemap-robots.min.js/wp-content/plugins/robots-sitemap/assets/js/jquery.dataTables.min.js/wp-content/plugins/robots-sitemap/assets/js/vo3da-plugin-position.js
Version Parameters
robots-sitemap/assets/css/sitemap-robots.min.css?ver=robots-sitemap/assets/css/jquery.dataTables.min.css?ver=robots-sitemap/assets/js/sitemap-robots.min.js?ver=robots-sitemap/assets/js/jquery.dataTables.min.js?ver=robots-sitemap/assets/js/vo3da-plugin-position.js?ver=

HTML / DOM Fingerprints

CSS Classes
sitemap-robots-container
Data Attributes
data-vo3da-robots-options
JS Globals
vo3da_save_sitemap_optionsvo3da_clear_sitemap_cachevo3da_get_robotsvo3da_update_robotsvo3da_replace_robots
REST Endpoints
/wp-json/robots-sitemap/v1/update-robots/wp-json/robots-sitemap/v1/clear-cache/wp-json/robots-sitemap/v1/get-robots/wp-json/robots-sitemap/v1/save-sitemap-options
FAQ

Frequently Asked Questions about Robots & Sitemap