
Amministrazione Trasparente Security & Risk Analysis
wordpress.org/plugins/amministrazione-trasparentePlugin completo per la gestione documentale di Amministrazione Trasparente nelle Pubbliche Amministrazioni (D.lgs. 33/2013)
Is Amministrazione Trasparente Safe to Use in 2026?
Generally Safe
Score 97/100Amministrazione Trasparente has a strong security track record. Known vulnerabilities have been patched promptly.
The "amministrazione-trasparente" plugin version 9.1 exhibits a mixed security posture. On the positive side, the static analysis reveals good practices such as the absence of dangerous functions, the use of prepared statements for all SQL queries, and a decent proportion of properly escaped output. The plugin also incorporates at least one nonce check and one capability check, which are crucial for preventing common web vulnerabilities.
However, concerns arise from the taint analysis, which identified one flow with an unsanitized path. While classified as not critical or high severity, this indicates a potential weakness where user-supplied data might be processed in an insecure manner, potentially leading to vulnerabilities if exploited. Furthermore, the plugin's history of three medium-severity CVEs, primarily involving Cross-site Scripting and Cross-Site Request Forgery, is a significant concern. The fact that the last vulnerability was very recent (2025-08-30) suggests a pattern of introducing exploitable flaws, even if they are consistently patched.
In conclusion, while the plugin demonstrates some strong security fundamentals, the presence of an unsanitized path in taint analysis and its history of medium-severity vulnerabilities necessitate careful attention. The plugin is not inherently insecure, but the recurring nature of past issues and the identified taint flow indicate areas that require diligent monitoring and potential further hardening to mitigate ongoing risks.
Key Concerns
- Taint flow with unsanitized path
- History of 3 medium severity CVEs
- 82% of outputs properly escaped (implies 18% not)
Amministrazione Trasparente Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Amministrazione Trasparente <= 9.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via print_r Function
Amministrazione Trasparente <= 8.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Amministrazione Trasparente <= 7.1 - Cross-Site Request Forgery Bypass
Amministrazione Trasparente Code Analysis
Output Escaping
Data Flow Analysis
Amministrazione Trasparente Attack Surface
Shortcodes 7
WordPress Hooks 30
Maintenance & Trust
Amministrazione Trasparente Maintenance & Trust
Maintenance Signals
Community Trust
Amministrazione Trasparente Alternatives
ANAC XML Viewer
anac-xml-viewer
Software per la visualizzazione di dataset XML su tracciato ANAC (ex AVCP -Legge 190/2012 Art 1.32).
Amministrazione Aperta
amministrazione-aperta
Software per la pubblicazione di concessioni (sovvenzioni, contributi, sussidi e vantaggi economici) e incarichi, anche in formato open data, come ric …
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Advanced Excerpt
advanced-excerpt
Control the appearance of WordPress post excerpts
WooCommerce Payfast Gateway
woocommerce-payfast-gateway
Give customers more flexibility and increase your bottom line with Payfast — one of South Africa’s most popular payment gateways.
Amministrazione Trasparente Developer Profile
13 plugins · 13K total installs
How We Detect Amministrazione Trasparente
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/amministrazione-trasparente/css/at-custom.css/wp-content/plugins/amministrazione-trasparente/css/at-style.css/wp-content/plugins/amministrazione-trasparente/css/datatable/dataTables.bootstrap.min.css/wp-content/plugins/amministrazione-trasparente/css/datatable/datatables.min.css/wp-content/plugins/amministrazione-trasparente/js/at-functions.js/wp-content/plugins/amministrazione-trasparente/js/datatable/dataTables.bootstrap.min.js/wp-content/plugins/amministrazione-trasparente/js/datatable/dataTables.min.js/wp-content/plugins/amministrazione-trasparente/js/at-functions.js/wp-content/plugins/amministrazione-trasparente/js/datatable/dataTables.min.js/wp-content/plugins/amministrazione-trasparente/js/datatable/dataTables.bootstrap.min.jsHTML / DOM Fingerprints
at-contentat-table-wrapper =========== SHORTCODES [at-head] & [at-desc] & [at-table] & [at-list] =========== data-at-idat_options/wp-json/amministrazione-trasparente/v1/config[at-head][at-desc][at-table][at-list]