
AnnunciFunebri Security & Risk Analysis
wordpress.org/plugins/annuncifunebri-onoranzaDisplay funeral announcements from annuncifunebri.it on your website for funeral homes using this service.
Is AnnunciFunebri Safe to Use in 2026?
Generally Safe
Score 99/100AnnunciFunebri has a strong security track record. Known vulnerabilities have been patched promptly.
The "annuncifunebri-onoranza" v4.8.3 plugin demonstrates a generally good security posture with robust practices in place. The high percentage of properly escaped outputs and the exclusive use of prepared statements for SQL queries are positive indicators. The absence of critical or high severity taint flows, along with no identified flows with unsanitized paths, suggests that common injection vulnerabilities are well-mitigated.
However, a notable concern exists with the REST API. One route is exposed without a permission callback, creating an unprotected entry point. While the static analysis did not reveal critical taint flows stemming from this, the lack of authorization on a REST API endpoint is a significant risk, as it could potentially be exploited by unauthenticated users if sensitive operations are exposed. The plugin also utilizes a "dangerous function" (preg_replace(/e)), which, if not handled with extreme care, can lead to code execution vulnerabilities.
The vulnerability history shows a single medium severity CVE, which is now patched. This indicates that while past vulnerabilities have existed, they have been addressed. The common vulnerability type being "Missing Authorization" aligns with the observed unprotected REST API route. Overall, the plugin has strengths in its data handling but requires immediate attention to its REST API security.
Key Concerns
- Unprotected REST API route
- Use of dangerous function (preg_replace(/e))
- Bundled library (Select2)
AnnunciFunebri Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
AnnunciFunebri Impresa <= 4.7.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Deletion
AnnunciFunebri Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
AnnunciFunebri Attack Surface
REST API Routes 1
Shortcodes 4
WordPress Hooks 60
Scheduled Events 1
Maintenance & Trust
AnnunciFunebri Maintenance & Trust
Maintenance Signals
Community Trust
AnnunciFunebri Alternatives
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Posts in Page
posts-in-page
Easily add one or more posts to any page using simple shortcodes.
Disable Author Pages
disable-author-pages
Disable the author pages
Menu In Post
menu-in-post
A simple but flexible plugin to allow the use of menus in posts and pages.
AnnunciFunebri Developer Profile
1 plugin · 100 total installs
How We Detect AnnunciFunebri
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/annuncifunebri-onoranza/css/annunci.css/wp-content/plugins/annuncifunebri-onoranza/css/owl.carousel.min.css/wp-content/plugins/annuncifunebri-onoranza/css/owl.theme.default.min.css/wp-content/plugins/annuncifunebri-onoranza/js/annunci.js/wp-content/plugins/annuncifunebri-onoranza/js/owl.carousel.min.js/wp-content/plugins/annuncifunebri-onoranza/js/annunci.js/wp-content/plugins/annuncifunebri-onoranza/js/owl.carousel.min.jsannuncifunebri-onoranza/css/annunci.css?ver=annuncifunebri-onoranza/css/owl.carousel.min.css?ver=annuncifunebri-onoranza/css/owl.theme.default.min.css?ver=annuncifunebri-onoranza/js/annunci.js?ver=annuncifunebri-onoranza/js/owl.carousel.min.js?ver=HTML / DOM Fingerprints
annuncifunebri-el-widget-wrapperannunci_data/wp-json/annuncifunebri-onoranza/v1/get_annunci[ANNFU_ANNUNCI][ANNFU_ANNUNCIO][ANNFU_DIRETTA][ANNFU_ULTIMI_ANNUNCI]