Intranet & Private Site – All-In-One Intranet Security & Risk Analysis

wordpress.org/plugins/all-in-one-intranet

Private intranet in one click. Auto-logout for security, login redirect, and multisite privacy controls included.

4K active installs v1.8.1 PHP 7.0+ WP 5.5+ Updated Mar 5, 2026
extranetintranetprivateprivate-siterestrict-access
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Intranet & Private Site – All-In-One Intranet Safe to Use in 2026?

Generally Safe

Score 100/100

Intranet & Private Site – All-In-One Intranet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 29d ago
Risk Assessment

The static analysis of the "all-in-one-intranet" plugin v1.8.1 reveals a generally positive security posture with strong adherence to best practices in several key areas. The plugin demonstrates a complete absence of external HTTP requests, file operations, and dangerous function usage, which significantly reduces its attack surface and potential for remote code execution or data manipulation. Furthermore, the high percentage of properly escaped output and the use of prepared statements for SQL queries are commendable, mitigating common vulnerabilities like cross-site scripting (XSS) and SQL injection.

However, there are a few areas that warrant attention. The presence of a single flow with an unsanitized path in the taint analysis, while not flagged as critical or high, indicates a potential for vulnerabilities related to file path traversal or insecure file handling. Additionally, the plugin has only one nonce check across all its code, and notably, zero capability checks. This absence of robust authorization checks on potential entry points is a significant concern, especially if any latent entry points exist that were not detected by the static analysis or if the single nonce check is not universally applied.

The plugin's vulnerability history is remarkably clean, with no recorded CVEs. This suggests a history of secure development and diligent maintenance. While this is a strong indicator of reliability, it's crucial to remember that past security is not a guarantee of future security. The combination of the unsanitized path flow and the minimal authorization checks presents a potential risk that could be exploited if a vulnerability is introduced in future updates or if the limited checks are bypassed. Overall, the plugin exhibits strong foundational security but requires vigilance regarding authorization and the identified taint flow.

Key Concerns

  • Flow with unsanitized path
  • Zero capability checks
  • Only one nonce check
Vulnerabilities
None known

Intranet & Private Site – All-In-One Intranet Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Intranet & Private Site – All-In-One Intranet Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
4
38 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

90% escaped42 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
aioi_check_activity (core\core_all_in_one_intranet.php:280)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Intranet & Private Site – All-In-One Intranet Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadmin_initcore\core_all_in_one_intranet.php:17
filternetwork_admin_plugin_action_linkscore\core_all_in_one_intranet.php:23
filterplugin_action_linkscore\core_all_in_one_intranet.php:25
actiontemplate_redirectcore\core_all_in_one_intranet.php:29
filterrobots_txtcore\core_all_in_one_intranet.php:30
filteroption_ping_sitescore\core_all_in_one_intranet.php:31
filterrest_pre_dispatchcore\core_all_in_one_intranet.php:32
filterxmlrpc_enabledcore\core_all_in_one_intranet.php:33
filterlogin_redirectcore\core_all_in_one_intranet.php:35
actionwp_logincore\core_all_in_one_intranet.php:37
actioninitcore\core_all_in_one_intranet.php:38
actionwpmu_new_usercore\core_all_in_one_intranet.php:41
actionwpmu_new_blogcore\core_all_in_one_intranet.php:42
Maintenance & Trust

Intranet & Private Site – All-In-One Intranet Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version7.0
Downloads127K

Community Trust

Rating100/100
Number of ratings10
Active installs4K
Developer Profile

Intranet & Private Site – All-In-One Intranet Developer Profile

Syed Balkhi

94 plugins · 23.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
795 days
View full developer profile
Detection Fingerprints

How We Detect Intranet & Private Site – All-In-One Intranet

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/all-in-one-intranet/assets/css/aioi-admin.css/wp-content/plugins/all-in-one-intranet/assets/css/aioi-login.css/wp-content/plugins/all-in-one-intranet/assets/js/aioi-admin.js
Script Paths
/wp-content/plugins/all-in-one-intranet/assets/js/aioi-admin.js
Version Parameters
all-in-one-intranet/assets/css/aioi-admin.css?ver=all-in-one-intranet/assets/css/aioi-login.css?ver=all-in-one-intranet/assets/js/aioi-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
aioi-admin-sectionaioi-login-logo
HTML Comments
<!-- All-In-One Intranet --><!-- Begin All-In-One Intranet -->
JS Globals
aioi_admin_script_vars
REST Endpoints
/wp-json/aioi/v1/settings
FAQ

Frequently Asked Questions about Intranet & Private Site – All-In-One Intranet