
GET API Manager Security & Risk Analysis
wordpress.org/plugins/get-api-managerProvides REST API endpoints for WooCommerce orders, blog posts, and pages, plus a setup wizard for API user/app password. Easily integrate your WooCom …
Is GET API Manager Safe to Use in 2026?
Generally Safe
Score 100/100GET API Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "get-api-manager" plugin v1.0 demonstrates a strong security posture in several key areas. The static analysis reveals no critical or high severity taint flows, and all SQL queries are properly prepared, indicating a good understanding of secure coding practices regarding data manipulation. Furthermore, the plugin implements nonce and capability checks on its AJAX handlers and REST API routes, and there are no known vulnerabilities (CVEs) associated with this version. This absence of past vulnerabilities suggests a proactive approach to security.
However, a significant concern arises from the output escaping. With only 33% of outputs properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts into the WordPress admin area or frontend that are rendered by the plugin, especially if user-supplied data is directly outputted without adequate sanitization. While the attack surface is limited and all entry points have authentication checks, the low percentage of properly escaped output is a critical weakness that requires immediate attention to mitigate XSS risks.
Key Concerns
- Low percentage of properly escaped output
GET API Manager Security Vulnerabilities
GET API Manager Code Analysis
SQL Query Safety
Output Escaping
GET API Manager Attack Surface
AJAX Handlers 3
REST API Routes 4
WordPress Hooks 8
Maintenance & Trust
GET API Manager Maintenance & Trust
Maintenance Signals
Community Trust
GET API Manager Alternatives
Products and Orders Last Modified for WC REST API
products-and-orders-last-modified-for-wc-rest-api
Retrieve Last Modified Products and Orders via WooCommerce REST API
WooCommerce Legacy REST API
woocommerce-legacy-rest-api
The WooCommerce Legacy REST API, which is now part of WooCommerce itself but will be removed in WooCommerce 9.0.
CoCart – Headless REST API for WooCommerce
cart-rest-api-for-woocommerce
A developer-first REST API to decouple WooCommerce on the frontend to help build modern and scalable storefronts. Fast, secure, customizable, easy.
WCFM – Multivendor Marketplace REST API for WooCommerce
wcfm-marketplace-rest-api
REST API for the most featured and powerful multi vendor plugin for your WooCommerce Multi-vendor Marketplace.
CoCart CORS Support
cocart-cors
Enables support for CORS to allow CoCart to work across multiple domains.
GET API Manager Developer Profile
1 plugin · 0 total installs
How We Detect GET API Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/get-api-manager/assets/css/admin.css/wp-content/plugins/get-api-manager/assets/js/admin.js/wp-content/plugins/get-api-manager/assets/js/admin.jsget-api-manager/assets/css/admin.css?ver=get-api-manager/assets/js/admin.js?ver=HTML / DOM Fingerprints
/wp-json/get-api-manager/v1/orders/wp-json/get-api-manager/v1/orders/(?P<id>\d+)/wp-json/get-api-manager/v1/posts/wp-json/get-api-manager/v1/pages