Aika Digital Assistance Security & Risk Analysis

wordpress.org/plugins/athlos-assistente-digitale

Usage and Definition

0 active installs v2.1 PHP + WP 5.9+ Updated Unknown
aiaikaathlosdigital-assistant
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Aika Digital Assistance Safe to Use in 2026?

Generally Safe

Score 100/100

Aika Digital Assistance has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the static analysis, the "athlos-assistente-digitale" v2.1 plugin exhibits a very strong security posture regarding its attack surface. There are no apparent entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are exposed to potential attackers. This significantly limits the plugin's susceptibility to direct exploitation. Furthermore, the absence of dangerous function calls and file operations is commendable.

However, a significant concern arises from the handling of SQL queries. All two identified SQL queries are not using prepared statements, indicating a potential risk of SQL injection vulnerabilities. While the taint analysis shows no unsanitized paths, this is likely due to the limited attack surface, and the raw SQL remains a significant risk. The low percentage of properly escaped output also suggests potential cross-site scripting (XSS) vulnerabilities, though the scope is limited.

The vulnerability history being completely clear with no recorded CVEs is a positive indicator. It suggests that the plugin developers may have a good track record or that the plugin has not been a significant target for past vulnerabilities. Despite the clean history, the identified code signals warrant attention, particularly the unparameterized SQL queries, which are a fundamental security flaw. Overall, while the plugin's design minimizes its attack surface, the lack of prepared statements for SQL queries and insufficient output escaping present clear and addressable security weaknesses.

Key Concerns

  • Raw SQL queries without prepared statements
  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Aika Digital Assistance Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Aika Digital Assistance Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
2
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

33% escaped3 total outputs
Attack Surface

Aika Digital Assistance Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninitindex.php:37
actionadmin_menuindex.php:45
actionwp_footerindex.php:109
Maintenance & Trust

Aika Digital Assistance Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedUnknown
PHP min version
Downloads749

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Aika Digital Assistance Developer Profile

paolofru

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Aika Digital Assistance

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/athlos-assistente-digitale/img/logo_viola.png/wp-content/plugins/athlos-assistente-digitale/img/close.webm
Script Paths
https://sdkathlos.it/avatar/freedemo/js_wordpress/sdk_main.js

HTML / DOM Fingerprints

CSS Classes
rowcolumn
Data Attributes
id="logo"id="assistente_id"id="closed_close"
FAQ

Frequently Asked Questions about Aika Digital Assistance