Dynamic XML Sitemaps Generator for Google Security & Risk Analysis

wordpress.org/plugins/xml-sitemap-generator-for-google

Boost SEO 🚀 with powerful XML, HTML, Image, Video & Google News sitemaps for better search engine indexing.

20K active installs v2.2.9 PHP 5.6+ WP 5.0+ Updated Mar 5, 2026
google-newsimage-sitemapsitemapvideo-sitemapxml-sitemap
100
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 28, 2023
Safety Verdict

Is Dynamic XML Sitemaps Generator for Google Safe to Use in 2026?

Generally Safe

Score 100/100

Dynamic XML Sitemaps Generator for Google has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 28, 2023Updated 29d ago
Risk Assessment

The 'xml-sitemap-generator-for-google' plugin, version 2.2.9, demonstrates a generally strong security posture with several positive indicators. The static analysis reveals no critical or high-severity taint flows, a very low percentage of SQL queries not using prepared statements, and an exceptionally high rate of proper output escaping. The plugin also implements a good number of nonce and capability checks across its entry points, which are all protected. However, the presence of one past medium-severity CVE, specifically a Cross-Site Request Forgery (CSRF), warrants attention. While this vulnerability is marked as patched, it highlights a historical area of weakness. The attack surface, though small and well-protected, consists entirely of AJAX handlers, meaning any future oversight in securing these could be exploited. The plugin's single file operation and external HTTP request, while not inherently risky, represent potential vectors if not handled with extreme care.

Key Concerns

  • Past medium severity CVE (CSRF)
Vulnerabilities
1

Dynamic XML Sitemaps Generator for Google Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-26514medium · 4.3Cross-Site Request Forgery (CSRF)

XML Sitemap Generator for Google <= 1.3.3 - Cross-Site Request Forgery to Plugin Settings Changes

Feb 28, 2023 Patched in 1.3.4 (329d)
Code Analysis
Analyzed Mar 16, 2026

Dynamic XML Sitemaps Generator for Google Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
9 prepared
Unescaped Output
20
581 escaped
Nonce Checks
5
Capability Checks
8
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

82% prepared11 total queries

Output Escaping

97% escaped601 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
import_settings (includes\ImportExport.php:12)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Dynamic XML Sitemaps Generator for Google Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_export_sitemap_settingsincludes\ImportExport.php:9
authwp_ajax_sgg_disable_noticeincludes\Notices.php:13
authwp_ajax_save_wizard_settingsincludes\Wizard.php:13
WordPress Hooks 35
actionplugins_loadedincludes\autoload.php:55
actionadmin_initincludes\Dashboard.php:14
actionadmin_menuincludes\Dashboard.php:15
filterplugin_row_metaincludes\Dashboard.php:17
actionadmin_enqueue_scriptsincludes\Dashboard.php:18
actionadmin_print_footer_scriptsincludes\Dashboard.php:19
filterquery_varsincludes\Frontend.php:17
actionparse_requestincludes\Frontend.php:18
actiondo_robotsincludes\Frontend.php:19
actionadmin_initincludes\Frontend.php:20
filteroption_rewrite_rulesincludes\Frontend.php:207
filterinstall_plugins_tabsincludes\helpers.php:174
filterxml_sitemap_news_languageincludes\hooks.php:37
filterxml_sitemap_news_languageincludes\hooks.php:58
filterxml_sitemap_include_postincludes\hooks.php:87
filtersgg_sitemap_exclude_single_termincludes\hooks.php:119
filtersgg_sitemap_post_media_urlsincludes\hooks.php:154
filterxml_media_sitemap_post_contentincludes\hooks.php:176
actionwpincludes\hooks.php:197
actiontransition_post_statusincludes\hooks.php:213
filterwp_sitemaps_enabledincludes\hooks.php:218
filterxml_sitemap_google_news_titleincludes\hooks.php:234
actionadmin_initincludes\Notices.php:12
actioncurrent_screenincludes\Notices.php:40
actionadmin_noticesincludes\Notices.php:49
actionadmin_noticesincludes\Notices.php:53
actioninitincludes\PostSettings.php:7
actionenqueue_block_editor_assetsincludes\PostSettings.php:8
actionadd_meta_boxesincludes\PostSettings.php:9
actionsave_postincludes\PostSettings.php:10
actionedit_attachmentincludes\PostSettings.php:11
filteruser_has_capincludes\PostSettings.php:12
actiontransition_post_statusincludes\Tools.php:9
actionadmin_menuincludes\Wizard.php:11
actionadmin_initincludes\Wizard.php:12
Maintenance & Trust

Dynamic XML Sitemaps Generator for Google Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version5.6
Downloads972K

Community Trust

Rating94/100
Number of ratings40
Active installs20K
Developer Profile

Dynamic XML Sitemaps Generator for Google Developer Profile

WP Grim

3 plugins · 40K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
221 days
View full developer profile
Detection Fingerprints

How We Detect Dynamic XML Sitemaps Generator for Google

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xml-sitemap-generator-for-google/assets/css/rate-banner.min.css/wp-content/plugins/xml-sitemap-generator-for-google/assets/fonts/icons/style.css/wp-content/plugins/xml-sitemap-generator-for-google/assets/fonts/albert_sans/fonts.css/wp-content/plugins/xml-sitemap-generator-for-google/assets/css/styles.min.css/wp-content/plugins/xml-sitemap-generator-for-google/assets/js/jquery-ui.min.js/wp-content/plugins/xml-sitemap-generator-for-google/assets/js/scripts.js
Script Paths
/wp-content/plugins/xml-sitemap-generator-for-google/assets/js/scripts.js
Version Parameters
xml-sitemap-generator-for-google/assets/css/rate-banner.min.css?ver=xml-sitemap-generator-for-google/assets/fonts/icons/style.css?ver=xml-sitemap-generator-for-google/assets/fonts/albert_sans/fonts.css?ver=xml-sitemap-generator-for-google/assets/css/styles.min.css?ver=xml-sitemap-generator-for-google/assets/js/jquery-ui.min.js?ver=xml-sitemap-generator-for-google/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
sgg-wrapsgg-settings
Data Attributes
data-grim-sg-settings
JS Globals
grimDatasgg
FAQ

Frequently Asked Questions about Dynamic XML Sitemaps Generator for Google