
Custom REST API Prefix Security & Risk Analysis
wordpress.org/plugins/custom-rest-api-prefixA simple plugin to customize the default WordPress REST API prefix.
Is Custom REST API Prefix Safe to Use in 2026?
Generally Safe
Score 85/100Custom REST API Prefix has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-rest-api-prefix" v1.0.1 plugin exhibits a strong static security posture with no identified attack surface entry points, dangerous functions, or direct SQL queries. The code analysis indicates adherence to good practices like using prepared statements for all SQL queries and proper output escaping, which significantly mitigates common web application vulnerabilities. The absence of file operations, external HTTP requests, and bundled libraries further contributes to its secure design.
However, a notable concern arises from the taint analysis, which revealed two flows with unsanitized paths. While these did not escalate to critical or high severity, they represent potential vectors for directory traversal or path manipulation attacks if a specific, unverified scenario were to occur. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a generally well-maintained codebase. Despite this clean history and excellent static analysis results, the presence of unsanitized paths warrants attention as a latent risk.
Key Concerns
- Flows with unsanitized paths found
Custom REST API Prefix Security Vulnerabilities
Custom REST API Prefix Code Analysis
Output Escaping
Data Flow Analysis
Custom REST API Prefix Attack Surface
WordPress Hooks 2
Maintenance & Trust
Custom REST API Prefix Maintenance & Trust
Maintenance Signals
Community Trust
Custom REST API Prefix Alternatives
WP REST Cache
wp-rest-cache
Enable caching of the WordPress REST API and auto-flush caches upon wp-admin editing.
REST API Log
wp-rest-api-log
WordPress plugin to log REST API requests and responses
REST API Toolbox
rest-api-toolbox
Allows tweaking of several REST API settings
WP API Menus
wp-api-menus
Extends WordPress WP REST API with new routes pointing to WordPress menus.
WP API SwaggerUI
wp-api-swaggerui
WordPress REST API with Swagger UI.
Custom REST API Prefix Developer Profile
2 plugins · 10 total installs
How We Detect Custom REST API Prefix
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
regular-textid="cra_prefix_setting"name="cra_prefix_setting"/api/wp-json