WP Sitemap Pages and Posts Security & Risk Analysis

wordpress.org/plugins/wp-sitemap-pages-and-posts

An easy way to add a sitemap on one of your pages becomes reality thanks to this WordPress plugin. Just use the shortcode [wpspap_sitemap] on any of y …

1K active installs v1.1.0 PHP 7.2+ WP 5.2+ Updated May 21, 2020
generatorhtml-sitemappage-listsite-mapsitemapshuvo66
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Sitemap Pages and Posts Safe to Use in 2026?

Generally Safe

Score 85/100

WP Sitemap Pages and Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The wp-sitemap-pages-and-posts plugin v1.1.0 exhibits a strong security posture based on the provided static analysis. The code appears to follow good security practices, with no dangerous functions, SQL queries utilizing prepared statements, and proper output escaping. Furthermore, the plugin has no recorded vulnerability history, indicating a sustained commitment to security by its developers. The limited attack surface, consisting of a single shortcode with no apparent unprotected entry points, further contributes to its positive security standing. However, it's important to note the absence of capability checks and nonce checks. While the current code may not immediately expose vulnerabilities due to its limited functionality and entry points, these are generally considered essential security mechanisms for robust WordPress plugins. Their absence represents a potential area for future risk if the plugin's functionality were to expand or if unforeseen attack vectors were discovered.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

WP Sitemap Pages and Posts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Sitemap Pages and Posts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP Sitemap Pages and Posts Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wpspap_sitemap] wp_sitemap.php:49
Maintenance & Trust

WP Sitemap Pages and Posts Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 21, 2020
PHP min version7.2
Downloads11K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

WP Sitemap Pages and Posts Developer Profile

shuvo66

2 plugins · 1K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Sitemap Pages and Posts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<ul><li><a href="
FAQ

Frequently Asked Questions about WP Sitemap Pages and Posts