
WP REST API Force SSL Security & Risk Analysis
wordpress.org/plugins/json-rest-api-force-sslForce WP REST API endpoints to only be served over HTTPS.
Is WP REST API Force SSL Safe to Use in 2026?
Generally Safe
Score 85/100WP REST API Force SSL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "json-rest-api-force-ssl" plugin v0.2.0 reveals a very clean codebase with no identified vulnerabilities or risky patterns. The plugin demonstrates excellent security practices, including the complete absence of dangerous functions, file operations, and external HTTP requests. Furthermore, all SQL queries are properly prepared, and all output is correctly escaped, mitigating common web application vulnerabilities. The attack surface is also minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed, and importantly, none of these entry points are unprotected.
Taint analysis shows zero identified flows, indicating that user input is not being improperly handled or used in a way that could lead to exploits. The plugin's vulnerability history is also clear, with no recorded CVEs. This lack of historical issues, combined with the positive static analysis, suggests a well-developed and secure plugin. However, the absence of nonce and capability checks on the limited entry points, while not a direct issue given their zero count, is a pattern to note for future development, as it could become a risk if entry points are added without proper security measures. Overall, this plugin presents a low-risk profile.
Key Concerns
- Missing nonce checks
- Missing capability checks
WP REST API Force SSL Security Vulnerabilities
WP REST API Force SSL Release Timeline
WP REST API Force SSL Code Analysis
WP REST API Force SSL Attack Surface
WordPress Hooks 1
Maintenance & Trust
WP REST API Force SSL Maintenance & Trust
Maintenance Signals
Community Trust
WP REST API Force SSL Alternatives
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
REST API Log
wp-rest-api-log
WordPress plugin to log REST API requests and responses
WP API Menus
wp-api-menus
Extends WordPress WP REST API with new routes pointing to WordPress menus.
SearchWP API
searchwp-api
Run advanced searches via the WordPress REST API and SearchWP.
WP-REST-API Menus
wp-rest-api-menus
Adds menu endpoints to core WP REST API.
WP REST API Force SSL Developer Profile
5 plugins · 2K total installs
How We Detect WP REST API Force SSL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/json-rest-api-force-ssl/json-rest-api-force-ssl.php