
Zaki Sitemap Security & Risk Analysis
wordpress.org/plugins/zaki-sitemapThat plugin allow you to create a sitemap of your site. Use [zakisitemap] shortcode
Is Zaki Sitemap Safe to Use in 2026?
Generally Safe
Score 85/100Zaki Sitemap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zaki-sitemap plugin v1.2 exhibits a generally positive security posture based on the provided static analysis. It demonstrates good practices by avoiding dangerous functions, not performing file operations or external HTTP requests, and having no known vulnerabilities. The complete absence of SQL queries is also a strong positive, as it eliminates the risk of SQL injection. However, a significant concern arises from the complete lack of output escaping. With 24 total outputs, none being properly escaped, this plugin presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data displayed on the frontend without proper sanitization could be exploited. Furthermore, the absence of nonce and capability checks, while mitigated by the current lack of unprotected entry points, leaves the shortcode vulnerable should future code additions or modifications inadvertently expose it. The vulnerability history being clean is encouraging, but the unescaped output is a critical oversight that needs immediate attention.
Key Concerns
- 0% output escaping
- No nonce checks
- No capability checks
Zaki Sitemap Security Vulnerabilities
Zaki Sitemap Code Analysis
Output Escaping
Zaki Sitemap Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Zaki Sitemap Maintenance & Trust
Maintenance Signals
Community Trust
Zaki Sitemap Alternatives
Page-list
page-list
[pagelist], [subpages], [siblings] and [pagelist_ext] shortcodes
Sitemap by BestWebSoft – WordPress XML Site Map Page Generator Plugin
google-sitemap-plugin
Generate and add XML sitemap to WordPress website. Help search engines index your blog.
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
Posts in Page
posts-in-page
Easily add one or more posts to any page using simple shortcodes.
Author Filters
author-filters
Author filters plugin integrates an author filter drop down to sort listing on post, page, custom post type in admin.
Zaki Sitemap Developer Profile
4 plugins · 70 total installs
How We Detect Zaki Sitemap
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zaki-sitemap/css/zaki-sitemap.css/wp-content/plugins/zaki-sitemap/js/zaki-sitemap.js/wp-content/plugins/zaki-sitemap/js/zaki-sitemap.jszaki-sitemap/css/zaki-sitemap.css?ver=zaki-sitemap/js/zaki-sitemap.js?ver=HTML / DOM Fingerprints
exclboxname="zaki_sitemap_options[label_pages]"name="zaki_sitemap_options[excl_pages][]"name="zaki_sitemap_options[label_categories]"name="zaki_sitemap_options[excl_categories][]"name="zaki_sitemap_options[label_posttype]"name="zaki_sitemap_options[excl_posttype][]"+1 more