
Forum REST API Security & Risk Analysis
wordpress.org/plugins/forum-rest-apiA simple REST API to retrieve forum-related data, including forums, topics, and replies.
Is Forum REST API Safe to Use in 2026?
Generally Safe
Score 92/100Forum REST API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "forum-rest-api" plugin version 1.0.0 exhibits a significant security risk due to its unprotected REST API routes. While the plugin demonstrates good practices in other areas, such as the absence of dangerous functions, proper SQL statement preparation, and output escaping, the direct exposure of three REST API routes without any permission callbacks is a major concern. This creates an easily accessible attack surface for unauthenticated users.
Static analysis revealed no critical taint flows, dangerous functions, or vulnerability history, which are positive indicators. However, the lack of nonce checks and capability checks, coupled with the unprotected REST API routes, means that any functionality exposed through these routes could be exploited by malicious actors without proper authorization. The plugin's current security posture is therefore compromised by this oversight, leaving it vulnerable to potential unauthorized data manipulation or access.
Key Concerns
- REST API routes without permission callbacks
- No nonce checks on entry points
- No capability checks on entry points
Forum REST API Security Vulnerabilities
Forum REST API Code Analysis
Forum REST API Attack Surface
REST API Routes 3
WordPress Hooks 1
Maintenance & Trust
Forum REST API Maintenance & Trust
Maintenance Signals
Community Trust
Forum REST API Alternatives
WooCommerce Legacy REST API
woocommerce-legacy-rest-api
The WooCommerce Legacy REST API, which is now part of WooCommerce itself but will be removed in WooCommerce 9.0.
Disable REST API
disable-json-api
Disable the use of the REST API on your website to site users. Now with User Role support!
Make Connector
integromat-connector
Make Connector. Make lets you design, build, and automate by connecting with WordPress in just a few clicks.
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
Disable WP REST API
disable-wp-rest-api
Disables the WP REST API for visitors not logged into WordPress.
Forum REST API Developer Profile
1 plugin · 0 total installs
How We Detect Forum REST API
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
/wp-json/bbpress/v1/forums/wp-json/bbpress/v1/topics/wp-json/bbpress/v1/replies