Title: chillpanda's Replies | WordPress.org

---

# chillpanda

  [  ](https://wordpress.org/support/users/chillpanda/)

 *   [Profile](https://wordpress.org/support/users/chillpanda/)
 *   [Topics Started](https://wordpress.org/support/users/chillpanda/topics/)
 *   [Replies Created](https://wordpress.org/support/users/chillpanda/replies/)
 *   [Reviews Written](https://wordpress.org/support/users/chillpanda/reviews/)
 *   [Topics Replied To](https://wordpress.org/support/users/chillpanda/replied-to/)
 *   [Engagements](https://wordpress.org/support/users/chillpanda/engagements/)
 *   [Favorites](https://wordpress.org/support/users/chillpanda/favorites/)

 Search replies:

## Forum Replies Created

Viewing 2 replies - 1 through 2 (of 2 total)

 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[XML Sitemap Generator for Google] Plugin removed from repository](https://wordpress.org/support/topic/plugin-removed-from-repository-10/)
 *  [chillpanda](https://wordpress.org/support/users/chillpanda/)
 * (@chillpanda)
 * [4 years, 5 months ago](https://wordpress.org/support/topic/plugin-removed-from-repository-10/page/2/#post-15560115)
 * [@fmosse](https://wordpress.org/support/users/fmosse/) Seeing as how the closure
   prevents downloading the plugin and that the new patch, noted as version 4.1.2
   was meant to patch the security issue, until we can update the plugin, it will
   continue to be a vulnerability that exists until it’s patched. So while I can’t
   say whether or not the inference is regarding a malicious plugin or a malicious
   actor exploiting the plugin, it’s probably better safe than sorry.
 * [@casi800](https://wordpress.org/support/users/casi800/) if you were to ask me,
   I wouldn’t be able to tell you. I still have it on my site primarily because 
   on the front end, the Author is appropriately showing someone that isn’t Arne,
   which lines up with part of the information that lists @[Auctollo ](https://profiles.wordpress.org/auctollo/)
   as the plugin’s current author, with credits still attributing Arne as normal.
   However, when clicking on Auctollo’s name from the plugins list, it still directs
   me to the amebrachholde.de website. It would seem his [last reply](https://wordpress.org/support/topic/offer-hook-filter-for-excluded-external-pages/#post-15123462)
   mentioned 4 months and a week ago that there would be a new rollout in the early
   part of [this] year. So while I do find their lack of reply to this thread to
   be somewhat suspicious, or any sort of reply being provided to the[ numerous other unanswered posts ](https://wordpress.org/support/view/no-replies/)
   albeit having updated the source code just a week ago, it’s really hard to say
   definitively whether or not the plugin has been compromised in some way.
    It 
   also doesn’t help that [the website](http://auctollo.com) listed for [@auctollo](https://wordpress.org/support/users/auctollo/)
   doesn’t seem to be working from my end. It’s also worth noting that although 
   Auctollo was at pone point actively replying to support related submissions going
   as far back as a year ago, it seems to consistently be a generic message of “
   Thank you for reaching out..” and “…our team is working on it”. I suppose it’s
   always better to be safe than sorry unless we can get some input from WordPress.
   org about plugin’s current status. Or if a developer could review [the code that was submitted](https://plugins.trac.wordpress.org/changeset/2706751)
   to help make sense of whether or not the new code may contain malicious code 
   or something. Otherwise, there are plenty of other substitutes that do the same
   thing available from the plug in repository. So, to be sure, I am removing it
   myself, just to be safe, and for now.
 * [@blazingmoonorg](https://wordpress.org/support/users/blazingmoonorg/) Thank 
   you Mr. Giesler for doing all that and relaying the information here. It’s definitely
   alarming and concerning to hear the lack of information surrounding the plugin.
   Interestingly enough, when taking precaution and logging in to remove the plugin
   after reading your text, it would seem the plugin had a notification on my WordPress
   dashboard asking me to fill out [a survey](https://docs.google.com/forms/d/e/1FAIpQLSdv3cQ6Xwc04w5awHMdL_rsriTGKl6tiUDI6fvwzZD2YEx7ug/viewform)
   linked to a Google Forms page. While I refrained from filling out the survey,
   there just seems to be too many parts of the matter that seem off and I’d rather
   be safe than sorry.
 * [@cdgweb](https://wordpress.org/support/users/cdgweb/) [@gadhiyaravi](https://wordpress.org/support/users/gadhiyaravi/)
   [@coyotech](https://wordpress.org/support/users/coyotech/) I have not found that
   file either, whilst my /mu-plugins/ directory appears to be empty from file manager.
   And, just to be safe I SSH’d into the server in case of hidden files and found
   it to be empty as well. However, admittedly, I had gone to check after removing
   the plugin already.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[XML Sitemap Generator for Google] Plugin removed from repository](https://wordpress.org/support/topic/plugin-removed-from-repository-10/)
 *  [chillpanda](https://wordpress.org/support/users/chillpanda/)
 * (@chillpanda)
 * [4 years, 5 months ago](https://wordpress.org/support/topic/plugin-removed-from-repository-10/#post-15545491)
 * I too genuinely shared the same concern upon seeing Wordfence flagging the item
   as no longer being available in the repository.
 * When looking into it myself, it was noted [here](https://www.arnebrachhold.de/projects/wordpress-plugins/google-xml-sitemaps-generator/changelog/),
   as others have mentioned, that maintenance was taken over by [w3edge](https://www.w3-edge.com/),
   which advertises W3Cache and actually from [Boldgrid ](https://www.boldgrid.com/)
   so that’s a little odd.
 * However, the original author, Arne Brachhold, last update their changelog on 
   their site as 4.0.9, an entry from 2017-07-24 and a look at the updates indicated
   a new version was updated 3 days ago for version 4.1.2 and notes addressing fixing
   a [security issue related to Cross-Site Scripting attacks on debug page](https://plugins.trac.wordpress.org/browser/google-sitemap-generator/trunk/sitemap-core.php)
   by a new contributor.
    More important, it’s noted that the plugin is [being renamed again](https://plugins.trac.wordpress.org/changeset?old_path=%2Fgoogle-sitemap-generator%2Ftrunk&old=1997535&new_path=%2Fgoogle-sitemap-generator%2Ftrunk&new=2706751&sfp_email=&sfph_mail=)
   to “XML Sitemaps Plugin for WordPress” by a new contributor so chances are it’s
   just under review. With that said, the new version does seem to have some significant
   changes so I imagine it’s just standard review process.
    -  This reply was modified 4 years, 5 months ago by [chillpanda](https://wordpress.org/support/users/chillpanda/).
      Reason: w3edge was mistaken credited with W3 Total Cache based on initial 
      view of the website, this was corrected

Viewing 2 replies - 1 through 2 (of 2 total)