
WP Realtime Sitemap Security & Risk Analysis
wordpress.org/plugins/wp-realtime-sitemapA sitemap plugin to make it easier for your site to show all your pages, posts, archives, categories and tags in an easy to read format.
Is WP Realtime Sitemap Safe to Use in 2026?
Generally Safe
Score 85/100WP Realtime Sitemap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-realtime-sitemap" v1.5.7 plugin exhibits a generally good security posture based on the provided static analysis. It lacks dangerous functions, uses prepared statements exclusively for SQL queries, and has no recorded vulnerabilities or CVEs, indicating a strong history of secure development. The plugin also has a minimal attack surface with only one entry point (a shortcode), and no external HTTP requests or file operations are performed, further reducing potential risks.
However, there are areas for improvement. A significant concern is the low percentage (36%) of properly escaped outputs. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is directly outputted without sufficient sanitization or escaping, especially when considering the shortcode as a potential entry point. Additionally, the absence of nonce checks on its single entry point, while not directly flagged by taint analysis, is a deviation from best practices for securing WordPress actions. The presence of capability checks, while positive, is not a substitute for proper nonce validation on user-initiated actions.
In conclusion, the plugin is likely secure against common server-side vulnerabilities due to its clean SQL practices and lack of external interactions. The primary residual risk stems from potential client-side XSS due to insufficient output escaping. The absence of nonce checks on the shortcode, while not a critical issue based on the provided taint analysis, represents a missed opportunity to further harden the plugin against potentially unintended actions.
Key Concerns
- Insufficient output escaping
- Missing nonce checks on shortcode
WP Realtime Sitemap Security Vulnerabilities
WP Realtime Sitemap Code Analysis
Output Escaping
WP Realtime Sitemap Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
WP Realtime Sitemap Maintenance & Trust
Maintenance Signals
Community Trust
WP Realtime Sitemap Alternatives
Dynamic HTML Sitemap
dynamic-html-sitemap
Generate a customizable, SEO-friendly HTML sitemap to improve your website’s navigation and visibility.
Easy Sitemap
easy-sitemap
Advanced HTML sitemap plugin with shortcode generator, intelligent caching, and comprehensive filtering for posts, pages, and custom post types.
NaviTree HTML Sitemap
navitree-html-sitemap
Automatically generates a dynamic HTML sitemap with multiple layouts (list, grid, accordion, tree), post type filtering, and styling options.
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
WP Realtime Sitemap Developer Profile
1 plugin · 10K total installs
How We Detect WP Realtime Sitemap
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-realtime-sitemap/css/admin-style.cssHTML / DOM Fingerprints
data-wp-realtime-sitemap-options[wp-realtime-sitemap]