
Intranet & Private Site – All-In-One Intranet Security & Risk Analysis
wordpress.org/plugins/all-in-one-intranetPrivate intranet in one click. Auto-logout for security, login redirect, and multisite privacy controls included.
Is Intranet & Private Site – All-In-One Intranet Safe to Use in 2026?
Generally Safe
Score 100/100Intranet & Private Site – All-In-One Intranet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "all-in-one-intranet" plugin v1.8.1 reveals a generally positive security posture with strong adherence to best practices in several key areas. The plugin demonstrates a complete absence of external HTTP requests, file operations, and dangerous function usage, which significantly reduces its attack surface and potential for remote code execution or data manipulation. Furthermore, the high percentage of properly escaped output and the use of prepared statements for SQL queries are commendable, mitigating common vulnerabilities like cross-site scripting (XSS) and SQL injection.
However, there are a few areas that warrant attention. The presence of a single flow with an unsanitized path in the taint analysis, while not flagged as critical or high, indicates a potential for vulnerabilities related to file path traversal or insecure file handling. Additionally, the plugin has only one nonce check across all its code, and notably, zero capability checks. This absence of robust authorization checks on potential entry points is a significant concern, especially if any latent entry points exist that were not detected by the static analysis or if the single nonce check is not universally applied.
The plugin's vulnerability history is remarkably clean, with no recorded CVEs. This suggests a history of secure development and diligent maintenance. While this is a strong indicator of reliability, it's crucial to remember that past security is not a guarantee of future security. The combination of the unsanitized path flow and the minimal authorization checks presents a potential risk that could be exploited if a vulnerability is introduced in future updates or if the limited checks are bypassed. Overall, the plugin exhibits strong foundational security but requires vigilance regarding authorization and the identified taint flow.
Key Concerns
- Flow with unsanitized path
- Zero capability checks
- Only one nonce check
Intranet & Private Site – All-In-One Intranet Security Vulnerabilities
Intranet & Private Site – All-In-One Intranet Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Intranet & Private Site – All-In-One Intranet Attack Surface
WordPress Hooks 13
Maintenance & Trust
Intranet & Private Site – All-In-One Intranet Maintenance & Trust
Maintenance Signals
Community Trust
Intranet & Private Site – All-In-One Intranet Alternatives
Private Site with Custom Login Page
private-website-intranet
Make your website private! Only logged in users can view your website. Perfect for intranets or in development websites.
My Private Site
jonradio-private-site
Make your WordPress site private with one click for family, projects, or teams. Protection for content, login, and registration.
Wbcom Designs – Private Community for BuddyPress
lock-my-bp
Create a private BuddyPress community by restricting access to non-members. Control who sees what with flexible privacy settings.
Private Website – Login Required
private-website
This plugin requires users to be logged in to view the website. Activate the plugin to enforce login, and deactivate it to remove the restriction.
wpNamedUsers
wpnamedusers
Intranet / Extranet plugin for Wordpress that allows users to specify which users and/or groups can access specific posts or pages.
Intranet & Private Site – All-In-One Intranet Developer Profile
94 plugins · 23.5M total installs
How We Detect Intranet & Private Site – All-In-One Intranet
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-in-one-intranet/assets/css/aioi-admin.css/wp-content/plugins/all-in-one-intranet/assets/css/aioi-login.css/wp-content/plugins/all-in-one-intranet/assets/js/aioi-admin.js/wp-content/plugins/all-in-one-intranet/assets/js/aioi-admin.jsall-in-one-intranet/assets/css/aioi-admin.css?ver=all-in-one-intranet/assets/css/aioi-login.css?ver=all-in-one-intranet/assets/js/aioi-admin.js?ver=HTML / DOM Fingerprints
aioi-admin-sectionaioi-login-logo<!-- All-In-One Intranet --><!-- Begin All-In-One Intranet -->aioi_admin_script_vars/wp-json/aioi/v1/settings