
GlotCore REST API Security & Risk Analysis
wordpress.org/plugins/glotcore-rest-apiExtends GlotPress with REST API endpoints for programmatic access to translation data.
Is GlotCore REST API Safe to Use in 2026?
Generally Safe
Score 100/100GlotCore REST API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The glotcore-rest-api plugin version 0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified attack surface entry points (AJAX handlers, REST API routes, shortcodes, cron events) is a significant positive. Furthermore, the code demonstrates excellent practices by utilizing prepared statements for all SQL queries and properly escaping all output. The plugin also incorporates a substantial number of capability checks, suggesting an intent to control access to its functionalities. The vulnerability history is also clean, with no known CVEs recorded.
However, the static analysis does reveal a critical lack of nonce checks across all entry points. While the analysis reports zero unprotected entry points and zero direct AJAX or REST API routes that are directly vulnerable due to missing permission callbacks, the absence of any nonce checks at all is a major concern. Nonces are a fundamental security mechanism in WordPress to prevent Cross-Site Request Forgery (CSRF) attacks. Their complete absence, even if the plugin appears to have no directly exposed endpoints in this specific analysis, creates a potential weakness that could be exploited if any functionality were to be inadvertently exposed or if the plugin's architecture changes in future versions. The complete lack of taint analysis flows could also be due to the limited scope of the analysis or the plugin's simplicity, but it means there's no confirmation of sanitization for data that might enter the system in ways not captured by the 'attack surface' metrics.
Key Concerns
- Complete absence of nonce checks
GlotCore REST API Security Vulnerabilities
GlotCore REST API Release Timeline
GlotCore REST API Code Analysis
SQL Query Safety
Output Escaping
GlotCore REST API Attack Surface
WordPress Hooks 3
Maintenance & Trust
GlotCore REST API Maintenance & Trust
Maintenance Signals
Community Trust
GlotCore REST API Alternatives
WPGet API – Connect to any external REST API
wpgetapi
Connect any REST API to WordPress. WPGet API enables easy API integration, allowing you to display API data without any code.
WP REST API Controller
wp-rest-api-controller
Enable a UI to toggle visibility and customize properties in WP REST API requests.
SMNTCS Disable REST API User Endpoints
smntcs-disable-rest-api-user-endpoints
Disable the REST API user endpoints due to obscure user slugs.
Custom API for WP
custom-api-for-wp
Connect WordPress with External APIs and create no-code custom WordPress REST API endpoints to interact with the WordPress database to perform SQL ope …
REST API Custom Fields
rest-api-custom-fields
This plugin enhances Wordpress REST API v2 responses about metadata
GlotCore REST API Developer Profile
16 plugins · 710 total installs
How We Detect GlotCore REST API
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
/wp-json/glotcore-rest-api/v1/formats/wp-json/glotcore-rest-api/v1/glossaries/wp-json/glotcore-rest-api/v1/glossary-entries/wp-json/glotcore-rest-api/v1/languages/wp-json/glotcore-rest-api/v1/originals/wp-json/glotcore-rest-api/v1/projects/wp-json/glotcore-rest-api/v1/project-permissions/wp-json/glotcore-rest-api/v1/profile/wp-json/glotcore-rest-api/v1/translations/wp-json/glotcore-rest-api/v1/translation-sets