Amministrazione Aperta Security & Risk Analysis

wordpress.org/plugins/amministrazione-aperta

Software per la pubblicazione di concessioni (sovvenzioni, contributi, sussidi e vantaggi economici) e incarichi, anche in formato open data, come ric …

200 active installs v3.8.2 PHP + WP 4.4+ Updated Oct 12, 2022
amministrazioneapertacomunipaspese
85
A · Safe
CVEs total1
Unpatched0
Last CVEMar 23, 2022
Safety Verdict

Is Amministrazione Aperta Safe to Use in 2026?

Generally Safe

Score 85/100

Amministrazione Aperta has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 23, 2022Updated 3yr ago
Risk Assessment

The plugin 'amministrazione-aperta' v3.8.2 exhibits a mixed security posture. On the positive side, the static analysis reveals good practices in its code. There are no identified dangerous functions, all SQL queries utilize prepared statements, and a high percentage of output is properly escaped. Furthermore, there are no file operations or external HTTP requests, and the attack surface from AJAX and REST API endpoints is effectively zero. However, the absence of nonce and capability checks on the identified entry points (shortcodes) is a significant concern. This means that any user, regardless of their role or permissions, could potentially trigger the functionality associated with these shortcodes, opening the door for unwanted actions or information disclosure.

The vulnerability history of this plugin is also noteworthy. The presence of one documented CVE, specifically an 'Improper Control of Filename for Include/Require Statement in PHP Program' (PHP Remote File Inclusion), indicates a past susceptibility to severe attacks. While this vulnerability is marked as currently unpatched, its nature suggests that if the plugin were to have similar flaws in current versions, it could lead to significant compromise. The plugin's strengths lie in its internal code quality regarding SQL and output handling, but the lack of robust access control on its entry points and its past RFI vulnerability warrant careful consideration.

Key Concerns

  • Missing capability checks on shortcodes
  • Past RFI vulnerability history
  • Bundled outdated library (DataTables)
Vulnerabilities
1

Amministrazione Aperta Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-1560medium · 5.4Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Amministrazione Aperta <= 3.7.3 - Admin+ Local File Inclusion

Mar 23, 2022 Patched in 3.8 (671d)
Code Analysis
Analyzed Mar 16, 2026

Amministrazione Aperta Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
70 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

Output Escaping

92% escaped76 total outputs
Attack Surface

Amministrazione Aperta Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[ammap] amministrazioneaperta.php:218
[aa] amministrazioneaperta.php:219
WordPress Hooks 13
actioninitamministrazioneaperta.php:29
actionadmin_initamministrazioneaperta.php:136
actioninitamministrazioneaperta.php:152
filterenter_title_hereamministrazioneaperta.php:189
actionadmin_initamministrazioneaperta.php:221
actionwp_enqueue_scriptsamministrazioneaperta.php:225
filterthe_contentamministrazioneaperta.php:230
actionadmin_initamministrazioneaperta.php:260
actionadd_meta_boxesfields_incarichi.php:75
actionsave_postfields_incarichi.php:76
actionadd_meta_boxesfields_spese.php:99
actionsave_postfields_spese.php:100
actionadmin_menusettings.php:9
Maintenance & Trust

Amministrazione Aperta Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedOct 12, 2022
PHP min version
Downloads13K

Community Trust

Rating100/100
Number of ratings3
Active installs200
Developer Profile

Amministrazione Aperta Developer Profile

Marco Milesi

13 plugins · 13K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
280 days
View full developer profile
Detection Fingerprints

How We Detect Amministrazione Aperta

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/amministrazione-aperta/js/admin-script.js/wp-content/plugins/amministrazione-aperta/css/admin-style.css/wp-content/plugins/amministrazione-aperta/css/style.css/wp-content/plugins/amministrazione-aperta/js/script.js
Script Paths
/wp-content/plugins/amministrazione-aperta/js/admin-script.js/wp-content/plugins/amministrazione-aperta/js/script.js
Version Parameters
amministrazione-aperta/css/admin-style.css?ver=amministrazione-aperta/js/admin-script.js?ver=amministrazione-aperta/css/style.css?ver=amministrazione-aperta/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
spesa-itemincarico-item
HTML Comments
<!-- AMMINISTRAZIONE APERTA -->
Data Attributes
data-spesa-iddata-incarico-id
JS Globals
amministrazione_aperta_params
Shortcode Output
[elenco_spese][elenco_incarichi]
FAQ

Frequently Asked Questions about Amministrazione Aperta