
Network Rest Site List Security & Risk Analysis
wordpress.org/plugins/network-rest-site-listSimple small Wordpress plugin that creates a REST endpoint to list all sites and their IDs in a Wordpress Multisite Network.
Is Network Rest Site List Safe to Use in 2026?
Generally Safe
Score 85/100Network Rest Site List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "network-rest-site-list" v1.0.0 exhibits a concerning security posture due to a significant unprotected entry point. While the code analysis shows positive signs like the absence of dangerous functions, the use of prepared statements for SQL queries, and proper output escaping, these strengths are overshadowed by the critical flaw in its REST API implementation. The single REST API route lacks any permission callback, meaning it is entirely unprotected and could potentially be accessed and manipulated by any unauthenticated user. This presents a serious risk of unauthorized access or data leakage. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this lack of history does not negate the immediate and evident risk posed by the unprotected REST API endpoint. In conclusion, while the plugin demonstrates good coding practices in many areas, the unprotected REST API route is a major security weakness that requires immediate attention.
Key Concerns
- Unprotected REST API route
- No capability checks on REST API route
Network Rest Site List Security Vulnerabilities
Network Rest Site List Release Timeline
Network Rest Site List Code Analysis
SQL Query Safety
Network Rest Site List Attack Surface
REST API Routes 1
WordPress Hooks 1
Maintenance & Trust
Network Rest Site List Maintenance & Trust
Maintenance Signals
Community Trust
Network Rest Site List Alternatives
REST API blocks
rest-api-blocks
Add gutenberg blocks data into the post / page REST API endpoints.
Disable REST API for Real
sar-disable-rest-api
Really prevents the REST API from handling requests (default) or require user to be logged in.
Talking Monkey Insights
tm-insights
Site health snapshot and REST monitoring API. Auto-detects WordFence/Defender, UpdraftPlus/Snapshot. Built for agencies running multiple sites.
Turn Off REST API
turn-off-rest-api
Disable the WordPress REST API for logged out visitors and lock down your /wp-json endpoints, with a per route allow list so you stay in control.
Disables unnecessary functionality
disable-unnecessary-functionality
Just disables unnecessary functionality of WordPress, thus improving and speeding up your site ^_^
Network Rest Site List Developer Profile
4 plugins · 210 total installs
How We Detect Network Rest Site List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
/ntwrkrst/v1/wpsitelist