
Network Rest Site List Security & Risk Analysis
wordpress.org/plugins/network-rest-site-listSimple small Wordpress plugin that creates a REST endpoint to list all sites and their IDs in a Wordpress Multisite Network.
Is Network Rest Site List Safe to Use in 2026?
Generally Safe
Score 85/100Network Rest Site List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "network-rest-site-list" v1.0.0 exhibits a concerning security posture due to a significant unprotected entry point. While the code analysis shows positive signs like the absence of dangerous functions, the use of prepared statements for SQL queries, and proper output escaping, these strengths are overshadowed by the critical flaw in its REST API implementation. The single REST API route lacks any permission callback, meaning it is entirely unprotected and could potentially be accessed and manipulated by any unauthenticated user. This presents a serious risk of unauthorized access or data leakage. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this lack of history does not negate the immediate and evident risk posed by the unprotected REST API endpoint. In conclusion, while the plugin demonstrates good coding practices in many areas, the unprotected REST API route is a major security weakness that requires immediate attention.
Key Concerns
- Unprotected REST API route
- No capability checks on REST API route
Network Rest Site List Security Vulnerabilities
Network Rest Site List Release Timeline
Network Rest Site List Code Analysis
SQL Query Safety
Network Rest Site List Attack Surface
REST API Routes 1
WordPress Hooks 1
Maintenance & Trust
Network Rest Site List Maintenance & Trust
Maintenance Signals
Community Trust
Network Rest Site List Alternatives
REST API blocks
rest-api-blocks
Add gutenberg blocks data into the post / page REST API endpoints.
Disable REST API for Real
sar-disable-rest-api
Really prevents the REST API from handling requests (default) or require user to be logged in.
Disables unnecessary functionality
disable-unnecessary-functionality
Just disables unnecessary functionality of WordPress, thus improving and speeding up your site ^_^
Custom API Creator
custom-api-creator
Custom API Creator is a WordPress plugin that lets developers create flexible, customize data, and control access with role restrictions.
Disable REST API (wp-json and oembed)
disable-rest-api-wp-json-and-oembed
This plugin disables wp-json and oembed mixed up with REST API
Network Rest Site List Developer Profile
4 plugins · 310 total installs
How We Detect Network Rest Site List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
/ntwrkrst/v1/wpsitelist