Wppao Sitemap Security & Risk Analysis

wordpress.org/plugins/wppao-sitemap

生成网站SEO所需要的Sitemap网站地图,支持xml和html格式的网站地图。

10K active installs v1.2.0 PHP 7.0+ WP 4.0+ Updated May 26, 2020
baiduseositemap
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wppao Sitemap Safe to Use in 2026?

Generally Safe

Score 85/100

Wppao Sitemap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "wppao-sitemap" v1.2.0 exhibits a generally positive security posture based on the provided static analysis. The absence of any identified CVEs in its vulnerability history is a strong indicator of good maintenance and prior security diligence. Furthermore, the code analysis reveals no dangerous functions, all SQL queries are properly prepared, and there are no identified taint flows with unsanitized paths, which are significant strengths. The plugin also demonstrates a lack of direct external HTTP requests and no bundled libraries, reducing potential attack vectors from third-party code.

However, there are notable areas for concern. A critical weakness is the complete lack of capability checks across any entry points, including the lack of permission callbacks for REST API routes and the absence of nonce checks on AJAX handlers (though there are currently none). This, combined with a low percentage of properly escaped output (31%), creates a significant risk. Even with a small attack surface currently identified, any future introduction of new entry points or existing ones that are not properly secured could lead to serious vulnerabilities. The presence of file operations without further context also warrants cautious consideration.

In conclusion, while "wppao-sitemap" benefits from a clean vulnerability history and good practices in SQL handling, its inadequate input validation and output escaping mechanisms represent a substantial risk. The lack of robust authentication and authorization on its entry points, even if currently minimal, is a fundamental security flaw that needs immediate attention to prevent potential exploitation should the attack surface expand or existing functions be leveraged maliciously.

Key Concerns

  • No capability checks on any entry points
  • Low percentage of properly escaped output
  • Lack of permission callbacks for REST API
  • Missing nonce checks on AJAX handlers
Vulnerabilities
None known

Wppao Sitemap Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wppao Sitemap Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
24
11 escaped
Nonce Checks
1
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

31% escaped35 total outputs
Attack Surface

Wppao Sitemap Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionpublish_postmodule\auto.php:4
actionpublish_postmodule\baidu-zd.php:41
filtermanage_posts_columnsmodule\baidu-zd.php:50
actionmanage_posts_custom_columnmodule\baidu-zd.php:56
filterwp_footermodule\js-ts.php:15
actionadmin_menuoptions\setting.php:21
Maintenance & Trust

Wppao Sitemap Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 26, 2020
PHP min version7.0
Downloads17K

Community Trust

Rating100/100
Number of ratings1
Active installs10K
Developer Profile

Wppao Sitemap Developer Profile

mryuanshu

2 plugins · 10K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wppao Sitemap

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wppao-sitemap/imgs/plugin_icon.png/wp-content/plugins/wppao-sitemap/css/wppao-pgs.css/wp-content/plugins/wppao-sitemap/js/wppao-pgs.js/wp-content/plugins/wppao-sitemap/js/wppao-custom.js
Script Paths
/wp-content/plugins/wppao-sitemap/module/js-ts.php
Version Parameters
wppao-sitemap/style.css?ver=wppao-sitemap/script.js?ver=wppao-pgs.css?ver=wppao-pgs.js?ver=wppao-custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
wppao-pgs-wrapwppao-pgs-headwppao-pgs-verwppao-pgs-contactwppao-pgs-author
Data Attributes
data-domaindata-versiondata-optiondata-slugdata-key
JS Globals
WppaoSitemap_Pluginwppao_pgs_pluginswppao_pgs_plugins_opt
Shortcode Output
<div class="wppao-pgs-ver">WP泡插件版本 V<h1>插件设置<small>WP泡网站地图
FAQ

Frequently Asked Questions about Wppao Sitemap