
API info for Plugins & Themes from WP.ORG Security & Risk Analysis
wordpress.org/plugins/api-info-themes-plugins-wp-org[ ✅ 𝐒𝐄𝐂𝐔𝐑𝐄 𝐏𝐋𝐔𝐆𝐈𝐍𝐒 b𝓎 𝒫𝓊𝓋𝑜𝓍 ] Show Plugins & Themes information on your site, from WP.ORG API
Is API info for Plugins & Themes from WP.ORG Safe to Use in 2026?
Generally Safe
Score 92/100API info for Plugins & Themes from WP.ORG has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "api-info-themes-plugins-wp-org" v1.13 exhibits a mixed security posture. On the positive side, the plugin has a zero attack surface exposed via AJAX handlers, REST API routes, shortcodes, or cron events, which is excellent for limiting direct entry points. Furthermore, a high percentage of SQL queries utilize prepared statements, and nonce and capability checks are present. However, several concerns arise from the static analysis. The presence of 15 dangerous functions, including `ini_set` and `unserialize`, raises red flags, especially when combined with a concerning taint analysis result of one high-severity flow with unsanitized paths. The fact that 53% of output is not properly escaped presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history indicates a past medium-severity XSS issue, which aligns with the unescaped output finding and suggests a pattern of potential input sanitization weaknesses. While there are no currently unpatched CVEs, the historical vulnerability and the static analysis findings warrant careful attention.
Overall, while the plugin demonstrates good practices in limiting its attack surface and using prepared statements, the identified dangerous functions, the high-severity taint flow with unsanitized paths, and the substantial proportion of unescaped output introduce significant risks. The past XSS vulnerability reinforces these concerns. The plugin's strengths in attack surface reduction are overshadowed by potential vulnerabilities in input handling and output sanitization. Continued vigilance and remediation of these identified issues are crucial for maintaining a secure environment.
Key Concerns
- High severity taint flow with unsanitized paths
- Significant portion of output not properly escaped
- Presence of dangerous functions (unserialize, ini_set)
- Past medium severity XSS vulnerability
API info for Plugins & Themes from WP.ORG Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
API info for Plugins & Themes from WP.ORG <= 1.04 - Reflected Cross-Site Scripting
API info for Plugins & Themes from WP.ORG Release Timeline
API info for Plugins & Themes from WP.ORG Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
API info for Plugins & Themes from WP.ORG Attack Surface
WordPress Hooks 33
Maintenance & Trust
API info for Plugins & Themes from WP.ORG Maintenance & Trust
Maintenance Signals
Community Trust
API info for Plugins & Themes from WP.ORG Alternatives
WPRS Data Transporter
wprs-data-transporter
Simply transfer your inputs Schema markups for reviews and star ratings data from one theme/plugin to another.
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
Theme Editor
theme-editor
Theme Editor allows you to edit theme files, create folder, upload files and remove any file and folder in themes and plugins.
Utimate Kit ( Styler ) for WPForms
styler-for-wpforms
Ultimate Kit for WPForms makes the task of designing WPForms an easy one.
Theme Check
theme-check
A simple and easy way to test your theme for all the latest WordPress standards and practices. A great theme development tool!
API info for Plugins & Themes from WP.ORG Developer Profile
19 plugins · 51K total installs
How We Detect API info for Plugins & Themes from WP.ORG
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/api-info-themes-plugins-wp-org/assets/script.js/wp-content/plugins/api-info-themes-plugins-wp-org/assets/style.css/wp-content/plugins/api-info-themes-plugins-wp-org/assets/script.js/wp-content/plugins/api-info-themes-plugins-wp-org/assets/script.js?ver=/wp-content/plugins/api-info-themes-plugins-wp-org/assets/style.css?ver=HTML / DOM Fingerprints
api-info-themes-plugins-wp-org-wrapper<!-- Individual Parameters to be obtained (below) --><!-- TODO --><!-- Displays the data from WP.ORG api --><!-- Should be either <code>plugins</code> or <code>themes</code> -->+13 moredata-typedata-bydata-by_valuedata-cache_timedata-return_only_datadata-cache_error_message+28 morewindow.api_info_themes_plugins_wp_org_obj[wporg_api_pt