Sitemap UI Security & Risk Analysis

wordpress.org/plugins/sitemap-ui

Sitemap UI for WordPress 5.5+

10 active installs v1.3 PHP + WP 5.5+ Updated Feb 12, 2022
configurationsettingssitemapsitemapsui
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Sitemap UI Safe to Use in 2026?

Generally Safe

Score 85/100

Sitemap UI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "sitemap-ui" v1.3 plugin exhibits a generally good security posture, with no known critical vulnerabilities in its history and a clean static analysis in many areas. The absence of CVEs suggests a history of secure development or diligent patching. The code analysis reveals strong practices like 100% prepared statements for SQL queries and a high percentage of properly escaped output. However, there are specific areas that warrant attention. The presence of one cron event could potentially be an entry point if not adequately secured, although the data indicates no unprotected entry points currently. A single flow with an unsanitized path in the taint analysis, even without a critical or high severity rating, represents a potential risk that should be investigated and remediated. The plugin also makes an external HTTP request, which could be a vector for certain attacks if the target is compromised or the request is mishandled. Finally, the lack of capability checks, while not explicitly identified as a vulnerability in this static analysis, is a general security concern that could lead to privilege escalation issues if not properly managed in conjunction with other WordPress security mechanisms.

Key Concerns

  • Flow with unsanitized path
  • External HTTP request
  • Lack of capability checks
Vulnerabilities
None known

Sitemap UI Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Sitemap UI Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Sitemap UI Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
9 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

90% escaped10 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
save_settings (sitemap-ui.php:111)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sitemap UI Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actioninitsitemap-ui.php:41
actionsmui_cronsitemap-ui.php:42
actionadmin_enqueue_scriptssitemap-ui.php:43
actionadmin_menusitemap-ui.php:63
filterwp_sitemaps_enabledsitemap-ui.php:140
filterwp_sitemaps_post_typessitemap-ui.php:146
filterwp_sitemaps_post_typessitemap-ui.php:150
filterwp_sitemaps_posts_query_argssitemap-ui.php:161
filterwp_sitemaps_taxonomiessitemap-ui.php:172
filterwp_sitemaps_taxonomiessitemap-ui.php:176
filterwp_sitemaps_taxonomies_query_argssitemap-ui.php:187
filterwp_sitemaps_users_query_argssitemap-ui.php:198

Scheduled Events 1

smui_cron
Maintenance & Trust

Sitemap UI Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedFeb 12, 2022
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Sitemap UI Developer Profile

Matt Gibbs

2 plugins · 2K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
475 days
View full developer profile
Detection Fingerprints

How We Detect Sitemap UI

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sitemap-ui/assets/vendor/fSelect/fSelect.js/wp-content/plugins/sitemap-ui/assets/js/admin.js/wp-content/plugins/sitemap-ui/assets/vendor/fSelect/fSelect.css/wp-content/plugins/sitemap-ui/assets/css/admin.css
Script Paths
/wp-content/plugins/sitemap-ui/assets/vendor/fSelect/fSelect.js/wp-content/plugins/sitemap-ui/assets/js/admin.js
Version Parameters
sitemap-ui/assets/vendor/fSelect/fSelect.js?ver=sitemap-ui/assets/js/admin.js?ver=sitemap-ui/assets/vendor/fSelect/fSelect.css?ver=sitemap-ui/assets/css/admin.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-select2-id
JS Globals
SMUI
FAQ

Frequently Asked Questions about Sitemap UI