
ANAC XML Viewer Security & Risk Analysis
wordpress.org/plugins/anac-xml-viewerSoftware per la visualizzazione di dataset XML su tracciato ANAC (ex AVCP -Legge 190/2012 Art 1.32).
Is ANAC XML Viewer Safe to Use in 2026?
Generally Safe
Score 98/100ANAC XML Viewer has a strong security track record. Known vulnerabilities have been patched promptly.
The "anac-xml-viewer" v1.8.3 plugin presents a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, raw SQL queries, file operations, or critical taint flows. All SQL queries are prepared, and the majority of output is properly escaped, indicating good development practices in these areas. There are no identified AJAX handlers or REST API routes without appropriate checks, and the total number of entry points is low.
However, several concerns warrant attention. The plugin has a history of two medium-severity vulnerabilities, specifically Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS). While there are currently no unpatched CVEs, the past occurrence of these common and impactful vulnerability types is a significant red flag. Furthermore, the complete absence of nonce checks and capability checks across the code signals a potential weakness. This lack of explicit authorization and integrity checks could be exploited if an attacker can manipulate inputs to trigger specific functions or processes, especially given the external HTTP request capability.
In conclusion, while the code itself appears to avoid some common pitfalls like raw SQL and dangerous functions, the historical vulnerability patterns and the absence of critical security checks like nonces and capability checks in the provided data point to a latent risk. The plugin should be carefully reviewed for any potential for input manipulation that could leverage the external HTTP request or bypass authorization mechanisms, even if no immediate critical vulnerabilities are detected in the current static analysis.
Key Concerns
- History of medium-severity CVEs (SSRF, XSS)
- No nonce checks detected
- No capability checks detected
- External HTTP request detected
- Partial output escaping (70%)
ANAC XML Viewer Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
ANAC XML Viewer <= 1.8.2 - Authenticated (Contributor+) Server-Side Request Forgery
ANAC XML Viewer <= 1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
ANAC XML Viewer Code Analysis
Output Escaping
ANAC XML Viewer Attack Surface
Shortcodes 2
WordPress Hooks 11
Maintenance & Trust
ANAC XML Viewer Maintenance & Trust
Maintenance Signals
Community Trust
ANAC XML Viewer Alternatives
Amministrazione Trasparente
amministrazione-trasparente
Plugin completo per la gestione documentale di Amministrazione Trasparente nelle Pubbliche Amministrazioni (D.lgs. 33/2013)
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
XML Sitemap Generator for Google
google-sitemap-generator
Generate multiple types of sitemaps to improve SEO and get your website indexed quickly.
ANAC XML Viewer Developer Profile
13 plugins · 13K total installs
How We Detect ANAC XML Viewer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/anac-xml-viewer/includes/excellentexport.min.js/wp-content/plugins/anac-xml-viewer/includes/excellentexport.min.jsHTML / DOM Fingerprints
light-table-filterdata-tabledata-tableexcellentExport[anac-xml id="[wpgov-xmlviewer id="