
TC SEO / Schema / Sitemap Security & Risk Analysis
wordpress.org/plugins/tc-seo-schema-sitemapTC SEO / Schema / Sitemap is a plugin that enhances your website’s SEO by adding google local business, SEO metadata, sitemap and optimizations.
Is TC SEO / Schema / Sitemap Safe to Use in 2026?
Generally Safe
Score 100/100TC SEO / Schema / Sitemap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of tc-seo-schema-sitemap v1.0.6 reveals a generally good security posture with no identified attack surface entry points, dangerous functions, file operations, or external HTTP requests. The absence of critical or high severity taint flows is also a positive sign. However, there are significant areas for concern. The plugin performs one SQL query that does not utilize prepared statements, which could be a vector for SQL injection if user-supplied data is directly incorporated into the query. Furthermore, a substantial 55% of its output is not properly escaped. This lack of robust output sanitization presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The complete lack of nonce checks and capability checks on its (currently zero) entry points, while not an immediate exploit due to the lack of entry points, indicates a potential weakness if new entry points are added without proper security considerations.
The vulnerability history is clean, with no known CVEs, which is commendable. This suggests that the developers may have a good understanding of security fundamentals or have been fortunate thus far. However, the absence of past vulnerabilities should not breed complacency, especially given the identified weaknesses in the current code. The key strengths lie in the minimal attack surface and lack of complex interactions, while the primary weaknesses stem from unescaped output and raw SQL queries. Addressing these issues is crucial to preventing potential security incidents.
Key Concerns
- SQL query not using prepared statements
- Significant portion of output not escaped
- Missing nonce checks
- Missing capability checks
TC SEO / Schema / Sitemap Security Vulnerabilities
TC SEO / Schema / Sitemap Code Analysis
SQL Query Safety
Output Escaping
TC SEO / Schema / Sitemap Attack Surface
WordPress Hooks 17
Maintenance & Trust
TC SEO / Schema / Sitemap Maintenance & Trust
Maintenance Signals
Community Trust
TC SEO / Schema / Sitemap Alternatives
ProRank SEO
prorank-seo
WordPress SEO and performance plugin with metadata, schema, sitemaps, redirects, audits, internal linking, image optimization, and speed tools.
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
SiteSEO – SEO Simplified
siteseo
SiteSEO is an easy, fast and powerful SEO plugin for WordPress. Unlock your Website's potential and Maximize your online visibility with our SiteSEO!
SureRank SEO – Smart Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
surerank
SureRank – SEO Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
TC SEO / Schema / Sitemap Developer Profile
1 plugin · 60 total installs
How We Detect TC SEO / Schema / Sitemap
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tc-seo-schema-sitemap/assets/tcss.css/wp-content/plugins/tc-seo-schema-sitemap/assets/tcss.js/wp-content/plugins/tc-seo-schema-sitemap/assets/tcss.jstc-seo-schema-sitemap/assets/tcss.css?ver=tc-seo-schema-sitemap/assets/tcss.js?ver=