TC SEO / Schema / Sitemap Security & Risk Analysis

wordpress.org/plugins/tc-seo-schema-sitemap

TC SEO / Schema / Sitemap is a plugin that enhances your website’s SEO by adding google local business, SEO metadata, sitemap and optimizations.

60 active installs v1.0.6 PHP 7.4+ WP 6.7+ Updated Jan 14, 2026
local-businessoptimizationschemaseositemap
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TC SEO / Schema / Sitemap Safe to Use in 2026?

Generally Safe

Score 100/100

TC SEO / Schema / Sitemap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The static analysis of tc-seo-schema-sitemap v1.0.6 reveals a generally good security posture with no identified attack surface entry points, dangerous functions, file operations, or external HTTP requests. The absence of critical or high severity taint flows is also a positive sign. However, there are significant areas for concern. The plugin performs one SQL query that does not utilize prepared statements, which could be a vector for SQL injection if user-supplied data is directly incorporated into the query. Furthermore, a substantial 55% of its output is not properly escaped. This lack of robust output sanitization presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The complete lack of nonce checks and capability checks on its (currently zero) entry points, while not an immediate exploit due to the lack of entry points, indicates a potential weakness if new entry points are added without proper security considerations.

The vulnerability history is clean, with no known CVEs, which is commendable. This suggests that the developers may have a good understanding of security fundamentals or have been fortunate thus far. However, the absence of past vulnerabilities should not breed complacency, especially given the identified weaknesses in the current code. The key strengths lie in the minimal attack surface and lack of complex interactions, while the primary weaknesses stem from unescaped output and raw SQL queries. Addressing these issues is crucial to preventing potential security incidents.

Key Concerns

  • SQL query not using prepared statements
  • Significant portion of output not escaped
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

TC SEO / Schema / Sitemap Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TC SEO / Schema / Sitemap Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
93
114 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

55% escaped207 total outputs
Attack Surface

TC SEO / Schema / Sitemap Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
filterpre_get_document_titleincludes\front.php:6
actionwp_headincludes\front.php:11
actionwp_footerincludes\front.php:341
actioninitincludes\front.php:484
actionwoocommerce_before_single_productincludes\front.php:495
actiontemplate_redirectincludes\front.php:500
actionshutdownincludes\front.php:504
filterwp_get_attachment_image_attributesincludes\front.php:595
filterwp_sitemaps_enabledincludes\front.php:619
actiontemplate_redirectincludes\front.php:630
filterwp_sitemaps_post_typesincludes\front.php:641
filterwp_sitemaps_taxonomiesincludes\front.php:659
filterwp_sitemaps_add_providerincludes\front.php:678
actionadmin_menutc-seo-schema-sitemap.php:22
actionadmin_enqueue_scriptstc-seo-schema-sitemap.php:45
actionadmin_inittc-seo-schema-sitemap.php:59
actionplugins_loadedtc-seo-schema-sitemap.php:196
Maintenance & Trust

TC SEO / Schema / Sitemap Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 14, 2026
PHP min version7.4
Downloads323

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

TC SEO / Schema / Sitemap Developer Profile

trianglecode

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TC SEO / Schema / Sitemap

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tc-seo-schema-sitemap/assets/tcss.css/wp-content/plugins/tc-seo-schema-sitemap/assets/tcss.js
Script Paths
/wp-content/plugins/tc-seo-schema-sitemap/assets/tcss.js
Version Parameters
tc-seo-schema-sitemap/assets/tcss.css?ver=tc-seo-schema-sitemap/assets/tcss.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about TC SEO / Schema / Sitemap