
Extension Access Manager Security & Risk Analysis
wordpress.org/plugins/extension-access-managerSecurely connect your Chrome extension to WordPress for uploading images and posting content via custom REST API.
Is Extension Access Manager Safe to Use in 2026?
Generally Safe
Score 100/100Extension Access Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "extension-access-manager" v1.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and all output is properly escaped. There are no recorded historical vulnerabilities, suggesting a potentially well-maintained or less targeted plugin. Furthermore, the absence of dangerous functions, file operations, and critical taint flows is a strong indicator of a secure codebase in these areas.
However, a significant concern arises from the presence of one unprotected REST API route. With a total of three REST API routes and only one lacking permission callbacks, this unprotected endpoint represents a direct attack vector. While the total attack surface is relatively small, this single unauthenticated entry point is a critical vulnerability. The absence of nonce checks and capability checks across all entry points further exacerbates this risk, as it allows for potential exploitation without proper authorization or request validation.
In conclusion, while the plugin has several strengths like secure SQL handling and output escaping, the unprotected REST API route is a critical flaw. The lack of comprehensive authorization checks on its entry points, despite a low historical vulnerability count, makes this plugin a moderate to high risk. Recommendations should focus on securing the identified REST API endpoint.
Key Concerns
- Unprotected REST API route
- Missing capability checks
- Missing nonce checks
Extension Access Manager Security Vulnerabilities
Extension Access Manager Code Analysis
Output Escaping
Extension Access Manager Attack Surface
REST API Routes 3
WordPress Hooks 5
Maintenance & Trust
Extension Access Manager Maintenance & Trust
Maintenance Signals
Community Trust
Extension Access Manager Alternatives
WooCommerce Legacy REST API
woocommerce-legacy-rest-api
The WooCommerce Legacy REST API, which is now part of WooCommerce itself but will be removed in WooCommerce 9.0.
Disable REST API
disable-json-api
Disable the use of the REST API on your website to site users. Now with User Role support!
Make Connector
integromat-connector
Make Connector. Make lets you design, build, and automate by connecting with WordPress in just a few clicks.
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
Disable WP REST API
disable-wp-rest-api
Disables the WP REST API for visitors not logged into WordPress.
Extension Access Manager Developer Profile
1 plugin · 0 total installs
How We Detect Extension Access Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extension-access-manager/assets/style.css/wp-content/plugins/extension-access-manager/assets/script.js/wp-content/plugins/extension-access-manager/assets/script.jsextension-access-manager/assets/style.css?ver=extension-access-manager/assets/script.js?ver=HTML / DOM Fingerprints
custom-api-settingsid="generate-uuid"id="exteacma_api_token"id="exteacma_api_username"id="exteacma_api_uuid"window.exteacma_download_image/exteacma/v1/verify-auth/exteacma/v1/post-article/exteacma/v1/upload-image