
Get Json Api Security & Risk Analysis
wordpress.org/plugins/get-json-apiRetrieve the results of the API of a site that uses the plugin JSON API
Is Get Json Api Safe to Use in 2026?
Generally Safe
Score 85/100Get Json Api has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The get-json-api plugin version 0.1 exhibits a generally good security posture based on the provided static analysis. It's notable that there are no detected dangerous functions, no raw SQL queries, and no external HTTP requests, which are common vectors for vulnerabilities. The absence of known CVEs and a history of vulnerabilities further reinforces this positive assessment. However, the plugin is not without its concerns. A significant weakness lies in the lack of nonce and capability checks, particularly as it has entry points (shortcodes) and a considerable percentage of its output is not properly escaped. While the attack surface is currently small (one shortcode) and has no direct unprotected AJAX or REST API routes, the lack of these fundamental security checks leaves it vulnerable to potential cross-site request forgery (CSRF) and cross-site scripting (XSS) attacks if the shortcode's functionality were to become more complex or process user-supplied data insecurely. The taint analysis showing zero flows is reassuring for now, but this is likely due to the limited scope of analysis and the plugin's current simplicity.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Significant unescaped output
Get Json Api Security Vulnerabilities
Get Json Api Code Analysis
Output Escaping
Get Json Api Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Get Json Api Maintenance & Trust
Maintenance Signals
Community Trust
Get Json Api Alternatives
IPGP Geolocation
ipgp-geolocation
Want to show different content based on user location, or to redirect certain users to another url ?
Motendo Widget
motendo-widget
Motendo Widget pozwala wyświetlać ogłoszenia z serwisu Motendo.com w postach, stronach i sidebarze.
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Kaya QR Code Generator
kaya-qr-code-generator
Generate QR Code through Widgets and Shortcodes, without any dependencies.
Get Json Api Developer Profile
3 plugins · 30 total installs
How We Detect Get Json Api
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/get-json-api/plugin/cycle/jquery.cycle2.min.js/wp-content/plugins/get-json-api/plugin/cycle/jquery.cycle2.autoheight.min.js/wp-content/plugins/get-json-api/css/get-json-api.css/wp-content/plugins/get-json-api/plugin/cycle/jquery.cycle2.min.js/wp-content/plugins/get-json-api/plugin/cycle/jquery.cycle2.autoheight.min.jsget-json-api/css/get-json-api.css?ver=plugin/cycle/jquery.cycle2.min.js?ver=plugin/cycle/jquery.cycle2.autoheight.min.js?ver=HTML / DOM Fingerprints
get-json-api-slideshowget-json-api-listcycle-slideshowui-icon-loadingdata-cycle-auto-heightserviceURLgetlist[getapi]