
API Write Blocker Security & Risk Analysis
wordpress.org/plugins/api-write-blockerA plugin to control the operation of admin-ajax.php, REST API, and xmlrpc.
Is API Write Blocker Safe to Use in 2026?
Generally Safe
Score 100/100API Write Blocker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "api-write-blocker" plugin v1.0 exhibits a strong security posture based on the provided static analysis. The plugin has a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, meaning there are no readily identifiable public entry points for attackers to exploit. Furthermore, the code demonstrates excellent security practices with no dangerous functions used, all SQL queries employing prepared statements, and 100% of output being properly escaped. The absence of file operations and external HTTP requests also minimizes potential attack vectors. The plugin also correctly implements a capability check, which is a positive sign of access control.
API Write Blocker Security Vulnerabilities
API Write Blocker Release Timeline
API Write Blocker Code Analysis
Output Escaping
API Write Blocker Attack Surface
WordPress Hooks 5
Maintenance & Trust
API Write Blocker Maintenance & Trust
Maintenance Signals
Community Trust
API Write Blocker Alternatives
No alternatives data available yet.
API Write Blocker Developer Profile
3 plugins · 0 total installs
How We Detect API Write Blocker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapform-tablemenu-listname="apiwrbl_is_enabled"name="apiwrbl_block_xmlrpc"name="apiwrbl_allowed_ip"name="apiwrbl_allowed_ajax_actions"name="apiwrbl_block_rest_post"name="apiwrbl_block_rest_put_patch"+8 more