Arha Routes Security & Risk Analysis

wordpress.org/plugins/arha-routes

Wordpress plugin that helps to serve content through REST routes and gives customizability to developers through filters.

10 active installs v1.5 PHP 7.1+ WP 5.0+ Updated May 15, 2020
bilingualendpointlanguagemultilingualrest
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Arha Routes Safe to Use in 2026?

Generally Safe

Score 85/100

Arha Routes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'arha-routes' plugin v1.5 exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack vectors like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's exposure to external manipulation. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions, file operations, or external HTTP requests. All SQL queries are properly prepared, and all outputs are correctly escaped, indicating robust data handling practices. The lack of any identified taint flows, regardless of severity, suggests that data is being sanitized effectively, preventing potential injection vulnerabilities.

The vulnerability history further reinforces this positive assessment, showing zero known CVEs. This lack of historical vulnerabilities, combined with the current clean code analysis, suggests a well-maintained and secure plugin. The absence of common vulnerability types and recent issues points to a consistent commitment to security by the developers. While the plugin has no capability checks or nonce checks, this is understandable given its zero attack surface; there are no obvious points where such checks would be immediately necessary without any exposed entry points.

In conclusion, the 'arha-routes' plugin v1.5 appears to be remarkably secure. Its strengths lie in its minimal attack surface and the diligent implementation of secure coding practices. The absence of any vulnerabilities, historical or identified in the static analysis, is a significant strength. The only potential area for improvement, though not a current risk due to the lack of attack vectors, would be to consider implementing capability checks if the plugin's functionality were to expand to include user-interactive features in the future. For its current state, the plugin is very low risk.

Vulnerabilities
None known

Arha Routes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Arha Routes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries
Attack Surface

Arha Routes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionrest_api_initarha-routes.php:27
Maintenance & Trust

Arha Routes Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedMay 15, 2020
PHP min version7.1
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Arha Routes Developer Profile

Atte Liimatainen

3 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Arha Routes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

REST Endpoints
/wp-json/arha/v1/page/wp-json/arha/v1/post/wp-json/arha/v1/options/wp-json/arha/v1/archive
FAQ

Frequently Asked Questions about Arha Routes