
Amministrazione Aperta Security & Risk Analysis
wordpress.org/plugins/amministrazione-apertaSoftware per la pubblicazione di concessioni (sovvenzioni, contributi, sussidi e vantaggi economici) e incarichi, anche in formato open data, come ric …
Is Amministrazione Aperta Safe to Use in 2026?
Generally Safe
Score 85/100Amministrazione Aperta has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'amministrazione-aperta' v3.8.2 exhibits a mixed security posture. On the positive side, the static analysis reveals good practices in its code. There are no identified dangerous functions, all SQL queries utilize prepared statements, and a high percentage of output is properly escaped. Furthermore, there are no file operations or external HTTP requests, and the attack surface from AJAX and REST API endpoints is effectively zero. However, the absence of nonce and capability checks on the identified entry points (shortcodes) is a significant concern. This means that any user, regardless of their role or permissions, could potentially trigger the functionality associated with these shortcodes, opening the door for unwanted actions or information disclosure.
The vulnerability history of this plugin is also noteworthy. The presence of one documented CVE, specifically an 'Improper Control of Filename for Include/Require Statement in PHP Program' (PHP Remote File Inclusion), indicates a past susceptibility to severe attacks. While this vulnerability is marked as currently unpatched, its nature suggests that if the plugin were to have similar flaws in current versions, it could lead to significant compromise. The plugin's strengths lie in its internal code quality regarding SQL and output handling, but the lack of robust access control on its entry points and its past RFI vulnerability warrant careful consideration.
Key Concerns
- Missing capability checks on shortcodes
- Past RFI vulnerability history
- Bundled outdated library (DataTables)
Amministrazione Aperta Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Amministrazione Aperta <= 3.7.3 - Admin+ Local File Inclusion
Amministrazione Aperta Code Analysis
Bundled Libraries
Output Escaping
Amministrazione Aperta Attack Surface
Shortcodes 2
WordPress Hooks 13
Maintenance & Trust
Amministrazione Aperta Maintenance & Trust
Maintenance Signals
Community Trust
Amministrazione Aperta Alternatives
Amministrazione Trasparente
amministrazione-trasparente
Plugin completo per la gestione documentale di Amministrazione Trasparente nelle Pubbliche Amministrazioni (D.lgs. 33/2013)
WP Mapa Politico España
wp-mapa-politico-spain
Inserta una imagen de un mapa político de España, con áreas definidas sobre las provincias sobre las que se pueden definir hipervínculos.
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Amministrazione Aperta Developer Profile
13 plugins · 13K total installs
How We Detect Amministrazione Aperta
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/amministrazione-aperta/js/admin-script.js/wp-content/plugins/amministrazione-aperta/css/admin-style.css/wp-content/plugins/amministrazione-aperta/css/style.css/wp-content/plugins/amministrazione-aperta/js/script.js/wp-content/plugins/amministrazione-aperta/js/admin-script.js/wp-content/plugins/amministrazione-aperta/js/script.jsamministrazione-aperta/css/admin-style.css?ver=amministrazione-aperta/js/admin-script.js?ver=amministrazione-aperta/css/style.css?ver=amministrazione-aperta/js/script.js?ver=HTML / DOM Fingerprints
spesa-itemincarico-item<!-- AMMINISTRAZIONE APERTA -->data-spesa-iddata-incarico-idamministrazione_aperta_params[elenco_spese][elenco_incarichi]