
MB Rest API Security & Risk Analysis
wordpress.org/plugins/mb-rest-apiGet and update Meta Box custom fields to the WordPress REST API responses.
Is MB Rest API Safe to Use in 2026?
Generally Safe
Score 100/100MB Rest API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mb-rest-api" plugin v2.0.6 demonstrates a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, combined with a lack of dangerous functions and file operations, significantly limits its attack surface. The fact that all SQL queries are properly prepared is a strong indicator of secure database interaction practices.
However, a notable concern arises from the output escaping. With 1 total output and 0% properly escaped, this presents a potential risk for Cross-Site Scripting (XSS) vulnerabilities if the output is user-controlled or dynamic. The presence of one capability check without any associated nonce checks on potential entry points (though none were identified) could be an area of improvement for more robust authorization, even if the current attack surface is minimal.
The plugin has no recorded vulnerabilities, CVEs, or history of past issues. This, coupled with the limited attack surface and secure SQL practices, suggests the developers have been diligent in maintaining security. However, the unescaped output remains the most significant identifiable risk that requires attention.
Key Concerns
- Output escaping is not implemented
MB Rest API Security Vulnerabilities
MB Rest API Code Analysis
Output Escaping
MB Rest API Attack Surface
WordPress Hooks 2
Maintenance & Trust
MB Rest API Maintenance & Trust
Maintenance Signals
Community Trust
MB Rest API Alternatives
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
MB Elementor Integration
mb-elementor-integrator
Integrates Meta Box's custom fields with Elementor page builder via dynamic tags.
Custom Fields for Gutenberg
custom-fields-gutenberg
Restores the Custom Field meta box for the Gutenberg Block Editor.
MB Yoast SEO Integration
meta-box-yoast-seo
Add content of Meta Box custom fields to Yoast SEO Content Analysis.
MB FacetWP Integration
meta-box-facetwp-integrator
Integrates Meta Box custom fields with FacetWP. Make custom fields filterable.
MB Rest API Developer Profile
17 plugins · 85K total installs
How We Detect MB Rest API
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mb-rest-api/src/assets/js/settings.js/wp-content/plugins/mb-rest-api/src/assets/css/settings.css/wp-content/plugins/mb-rest-api/src/assets/js/settings.jsmb-rest-api/src/assets/css/settings.css?ver=mb-rest-api/src/assets/js/settings.js?ver=HTML / DOM Fingerprints
mbRestApiSettings/meta-box/v1/settings-page//meta-box/v1/post//meta-box/v1/term//meta-box/v1/user//meta-box/v1/comment/