
Advanced Custom Routes – Custom Endpoints for WP REST API Security & Risk Analysis
wordpress.org/plugins/advanced-custom-routes-custom-endpoints-for-wp-rest-apiThe easiest way to create custom WP REST API Routes without writing a line of code.
Is Advanced Custom Routes – Custom Endpoints for WP REST API Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Custom Routes – Custom Endpoints for WP REST API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "advanced-custom-routes-custom-endpoints-for-wp-rest-api" version 0.8.0 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface. Furthermore, no dangerous functions, file operations, or external HTTP requests were detected, and there are no known CVEs associated with this plugin. However, significant concerns arise from the code analysis. The single SQL query is not using prepared statements, which presents a risk of SQL injection. A substantial portion of output (83%) is not properly escaped, opening the door to Cross-Site Scripting (XSS) vulnerabilities. The taint analysis indicates two flows with unsanitized paths, though they are not classified as critical or high severity in this report. The complete absence of nonce and capability checks across all identified entry points, coupled with the lack of output escaping, are critical omissions that significantly elevate the risk profile despite the limited reported attack surface and absence of known vulnerabilities.
Key Concerns
- SQL queries not using prepared statements
- Large amount of unescaped output
- No nonce checks found
- No capability checks found
- Taint flows with unsanitized paths
Advanced Custom Routes – Custom Endpoints for WP REST API Security Vulnerabilities
Advanced Custom Routes – Custom Endpoints for WP REST API Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced Custom Routes – Custom Endpoints for WP REST API Attack Surface
WordPress Hooks 13
Maintenance & Trust
Advanced Custom Routes – Custom Endpoints for WP REST API Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Custom Routes – Custom Endpoints for WP REST API Alternatives
Custom API for WP
custom-api-for-wp
Connect WordPress with External APIs and create no-code custom WordPress REST API endpoints to interact with the WordPress database to perform SQL ope …
REST API Manager For ACF
rest-api-manager-for-acf
Custom REST API endpoint plugin to return ACF fields, post meta (selected keys), or a mixed object. Fully configurable from the admin settings page.
SapientSEO
sapientseo
Adds secured custom REST API endpoints to integrate WordPress with the SapientSEO app.
WooCommerce Legacy REST API
woocommerce-legacy-rest-api
The WooCommerce Legacy REST API, which is now part of WooCommerce itself but will be removed in WooCommerce 9.0.
Disable REST API
disable-json-api
Disable the use of the REST API on your website to site users. Now with User Role support!
Advanced Custom Routes – Custom Endpoints for WP REST API Developer Profile
1 plugin · 40 total installs
How We Detect Advanced Custom Routes – Custom Endpoints for WP REST API
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-custom-routes-custom-endpoints-for-wp-rest-api/admin/lib/css/dist/styles.css/wp-content/plugins/advanced-custom-routes-custom-endpoints-for-wp-rest-api/admin/lib/js/scripts.jshttps://cdnjs.cloudflare.com/ajax/libs/select2/4.0.7/js/select2.min.jsHTML / DOM Fingerprints
/wp-json/acr/v1/custom-route