Disable Permanently REST API Security & Risk Analysis

wordpress.org/plugins/disable-permanently-rest-api

The most simple plugin to disable permanently REST API on WordPress 4.7+

0 active installs v0.1.1 PHP + WP 4.7+ Updated Unknown
disablejsonrestrest-apiwp-json
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Disable Permanently REST API Safe to Use in 2026?

Generally Safe

Score 100/100

Disable Permanently REST API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "disable-permanently-rest-api" v0.1.1 demonstrates an exceptionally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events, along with zero dangerous functions, SQL queries, file operations, or external HTTP requests, significantly minimizes the plugin's attack surface. Furthermore, the code signals indicate that all queries utilize prepared statements and all output is properly escaped, which are critical best practices for preventing common web vulnerabilities. The lack of any recorded vulnerabilities in its history further reinforces this positive assessment.

While the plugin excels in preventing common attack vectors through its minimal design and adherence to secure coding principles, the total absence of nonce checks and capability checks is a notable omission. In scenarios where the plugin might evolve or interact with other components in a more complex manner, these checks would become essential for robust access control. However, given the plugin's apparent sole purpose of disabling features (which typically doesn't require granular user permissions or AJAX interactions in its core function), this omission doesn't represent an immediate, exploitable risk based on the current analysis.

In conclusion, the plugin "disable-permanently-rest-api" v0.1.1 appears to be very secure and well-developed from a security perspective. Its strengths lie in its minimal attack surface and diligent use of prepared statements and output escaping. The lack of vulnerability history and zero critical findings in static analysis are highly encouraging. The only minor concern, the absence of nonce and capability checks, is contextual to its simple functionality and does not currently present a discernible security threat.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Disable Permanently REST API Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Disable Permanently REST API Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Disable Permanently REST API Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterrest_authentication_errorsdisable-permanently-rest-api.php:22
Maintenance & Trust

Disable Permanently REST API Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Disable Permanently REST API Developer Profile

Salvatore Cordiano

2 plugins · 20K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Disable Permanently REST API

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Disable Permanently REST API