
Intranet & Private Site – All-In-One Intranet Security & Risk Analysis
wordpress.org/plugins/all-in-one-intranetTurn WordPress into a private intranet in one click. Restrict access to logged-in members, with auto-logout and login redirect.
Is Intranet & Private Site – All-In-One Intranet Safe to Use in 2026?
Generally Safe
Score 99/100Intranet & Private Site – All-In-One Intranet has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The static analysis of the "all-in-one-intranet" plugin v1.8.1 reveals a generally positive security posture with strong adherence to best practices in several key areas. The plugin demonstrates a complete absence of external HTTP requests, file operations, and dangerous function usage, which significantly reduces its attack surface and potential for remote code execution or data manipulation. Furthermore, the high percentage of properly escaped output and the use of prepared statements for SQL queries are commendable, mitigating common vulnerabilities like cross-site scripting (XSS) and SQL injection.
However, there are a few areas that warrant attention. The presence of a single flow with an unsanitized path in the taint analysis, while not flagged as critical or high, indicates a potential for vulnerabilities related to file path traversal or insecure file handling. Additionally, the plugin has only one nonce check across all its code, and notably, zero capability checks. This absence of robust authorization checks on potential entry points is a significant concern, especially if any latent entry points exist that were not detected by the static analysis or if the single nonce check is not universally applied.
The plugin's vulnerability history is remarkably clean, with no recorded CVEs. This suggests a history of secure development and diligent maintenance. While this is a strong indicator of reliability, it's crucial to remember that past security is not a guarantee of future security. The combination of the unsanitized path flow and the minimal authorization checks presents a potential risk that could be exploited if a vulnerability is introduced in future updates or if the limited checks are bypassed. Overall, the plugin exhibits strong foundational security but requires vigilance regarding authorization and the identified taint flow.
Key Concerns
- Flow with unsanitized path
- Zero capability checks
- Only one nonce check
Intranet & Private Site – All-In-One Intranet Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Intranet & Private Site – All-In-One Intranet <= 1.8.1 - Missing Authorization
Intranet & Private Site – All-In-One Intranet Release Timeline
Intranet & Private Site – All-In-One Intranet Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Intranet & Private Site – All-In-One Intranet Attack Surface
WordPress Hooks 13
Maintenance & Trust
Intranet & Private Site – All-In-One Intranet Maintenance & Trust
Maintenance Signals
Community Trust
Intranet & Private Site – All-In-One Intranet Alternatives
Private Site with Custom Login Page
private-website-intranet
Make your website private! Only logged in users can view your website. Perfect for intranets or in development websites.
My Private Site – Make Your Whole Site Private, Force Login & Block Registration Spam
jonradio-private-site
Make your WordPress site private in one click, block registration spam, and clean up existing spam accounts with staged safeguards that protect online …
Private Website – Login Required
private-website
This plugin requires users to be logged in to view the website. Activate the plugin to enforce login, and deactivate it to remove the restriction.
PrimePlaced – Advanced password protection
primeplaced-advanced-password-protection
Lock your entire WordPress site behind a single password with a branded lock screen, session or timed access, and simple admin controls.
Full Site Login
full-site-login
Force users to log in before viewing any part of your WordPress site.
Intranet & Private Site – All-In-One Intranet Developer Profile
97 plugins · 22.5M total installs
How We Detect Intranet & Private Site – All-In-One Intranet
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-in-one-intranet/assets/css/aioi-admin.css/wp-content/plugins/all-in-one-intranet/assets/css/aioi-login.css/wp-content/plugins/all-in-one-intranet/assets/js/aioi-admin.js/wp-content/plugins/all-in-one-intranet/assets/js/aioi-admin.jsall-in-one-intranet/assets/css/aioi-admin.css?ver=all-in-one-intranet/assets/css/aioi-login.css?ver=all-in-one-intranet/assets/js/aioi-admin.js?ver=HTML / DOM Fingerprints
aioi-admin-sectionaioi-login-logo<!-- All-In-One Intranet --><!-- Begin All-In-One Intranet -->aioi_admin_script_vars/wp-json/aioi/v1/settings