
WP Sitemap Security & Risk Analysis
wordpress.org/plugins/wpsitemapSimple use shortcode [sitemap type="post"] or [sitemap type="page"]
Is WP Sitemap Safe to Use in 2026?
Use With Caution
Score 64/100WP Sitemap has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The WPSitemap plugin v1.0.0 exhibits a mixed security posture. On the positive side, the static analysis reveals excellent coding practices regarding SQL queries and output escaping, with 100% of queries using prepared statements and all outputs being properly escaped. There are no identified dangerous functions or file operations. However, a significant concern arises from the absence of nonce checks and capability checks. While the attack surface is currently small (one shortcode), the lack of these critical security measures leaves it vulnerable to various attacks if not properly handled within the shortcode's implementation. Furthermore, the plugin has a known vulnerability history, with one unpatched medium severity CVE related to Cross-Site Scripting (XSS). This indicates a recurring weakness that needs immediate attention.
Key Concerns
- Unpatched CVE (Medium Severity)
- Missing Nonce Checks
- Missing Capability Checks
WP Sitemap Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Sitemap <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Sitemap Release Timeline
WP Sitemap Code Analysis
WP Sitemap Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
WP Sitemap Maintenance & Trust
Maintenance Signals
Community Trust
WP Sitemap Alternatives
WP Sitemap Page
wp-sitemap-page
Add a sitemap on any of your page using the simple shortcode [wp_sitemap_page]. Improve the SEO and navigation of your website.
WP Sitemap Pages and Posts
wp-sitemap-pages-and-posts
An easy way to add a sitemap on one of your pages becomes reality thanks to this WordPress plugin. Just use the shortcode [wpspap_sitemap] on any of y …
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Page-list
page-list
[pagelist], [subpages], [siblings] and [pagelist_ext] shortcodes
Sitemap by BestWebSoft – WordPress XML Site Map Page Generator Plugin
google-sitemap-plugin
Generate and add XML sitemap to WordPress website. Help search engines index your blog.
WP Sitemap Developer Profile
5 plugins · 630 total installs
How We Detect WP Sitemap
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpsitemap/css/wp-sitemap.cssHTML / DOM Fingerprints
wp_sitemapwp_sitemap_itemwpsstyle-1wpsstyle-2wpsstyle-3<div id="wp_sitemap"><ul id="wp_sitemap_item" class="wpsstyle-"><li><a href="