Custom API Creator Security & Risk Analysis

wordpress.org/plugins/custom-api-creator

Custom API Creator is a WordPress plugin that lets developers create flexible, customize data, and control access with role restrictions.

10 active installs v1.0.4 PHP 7.0+ WP 5.0+ Updated Oct 7, 2024
apiapi-buildercustom-apirest-apiwp-json
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom API Creator Safe to Use in 2026?

Generally Safe

Score 92/100

Custom API Creator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The custom-api-creator plugin exhibits a very strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, file operations, or external HTTP requests is highly commendable. Furthermore, the extensive use of prepared statements for SQL queries and the near-perfect output escaping demonstrate excellent secure coding practices. The presence of both nonce and capability checks indicates a deliberate effort to protect against common WordPress vulnerabilities. The plugin's vulnerability history is also clean, with no recorded CVEs, suggesting a history of secure development and maintenance. While the taint analysis shows no critical or high-severity flows, it's important to note that the analysis might be limited by the lack of identified entry points in the static analysis. Overall, this plugin appears to be developed with security as a high priority.

Vulnerabilities
None known

Custom API Creator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Custom API Creator Release Timeline

v1.0.4Current
v1.0.3
Code Analysis
Analyzed Mar 17, 2026

Custom API Creator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
41 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped42 total outputs
Attack Surface

Custom API Creator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninitcustom-api-creator.php:21
actioninitcustom-api-creator.php:22
actionadmin_menucustom-api-creator.php:23
actionrest_api_initcustom-api-creator.php:24
actionadd_meta_boxescustom-api-creator.php:25
actionsave_postcustom-api-creator.php:26
actionadmin_enqueue_scriptscustom-api-creator.php:27
filtermanage_cac_plugin_posts_columnscustom-api-creator.php:30
actionmanage_cac_plugin_posts_custom_columncustom-api-creator.php:31
Maintenance & Trust

Custom API Creator Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 7, 2024
PHP min version7.0
Downloads629

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Custom API Creator Developer Profile

Mehdi Rezaei

3 plugins · 60 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom API Creator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-api-creator/assets/js/script.js
Script Paths
/wp-content/plugins/custom-api-creator/assets/js/script.js
Version Parameters
custom-api-creator/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
api-section
Data Attributes
data-index
REST Endpoints
/wp-json/wp/v2/cac_plugin
FAQ

Frequently Asked Questions about Custom API Creator