
Puti Content Core Security & Risk Analysis
wordpress.org/plugins/puti-content-coreA simple REST API plugin to embed content snippets from WordPress onto any external static website using JavaScript.
Is Puti Content Core Safe to Use in 2026?
Generally Safe
Score 100/100Puti Content Core has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The puti-content-core plugin version 1.1.0 exhibits a generally good security posture due to the absence of known vulnerabilities and critical taint analysis findings. The plugin also demonstrates good practices by using prepared statements for all SQL queries and performing capability checks. However, there are notable concerns regarding its attack surface and output escaping. Specifically, one of the three REST API routes lacks a permission callback, creating a potential entry point for unauthenticated access. Additionally, a significant portion (33%) of output operations are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. While the plugin has no recorded vulnerability history, this doesn't guarantee future safety, especially given the identified weaknesses. In conclusion, the plugin shows promise with its secure SQL handling and lack of past major flaws, but the presence of an unprotected REST API route and insufficient output escaping warrants attention and improvement to solidify its security.
Key Concerns
- REST API route without permission callback
- Significant percentage of unescaped output
Puti Content Core Security Vulnerabilities
Puti Content Core Release Timeline
Puti Content Core Code Analysis
Output Escaping
Puti Content Core Attack Surface
REST API Routes 3
WordPress Hooks 17
Maintenance & Trust
Puti Content Core Maintenance & Trust
Maintenance Signals
Community Trust
Puti Content Core Alternatives
WPGraphQL
wp-graphql
WPGraphQL adds a flexible and powerful GraphQL API to WordPress, enabling efficient querying and interaction with your site's data.
Automatik Blog
automatik-blog
A plugin for integration with Automatik Blog, allowing automated publishing of SEO-optimized articles via REST API.
BabyLoveGrowth Integration
babylovegrowth-integration
Secure REST endpoint to publish posts from BabyLoveGrowth.ai backend via API key.
CoCart – Headless REST API for WooCommerce
cart-rest-api-for-woocommerce
A developer-first REST API to decouple WooCommerce on the frontend to help build modern and scalable storefronts. Fast, secure, customizable, easy.
Logged-in-only
wp-logged-in-only
A Plugin to lock down the whole site to prevent public access.
Puti Content Core Developer Profile
1 plugin · 0 total installs
How We Detect Puti Content Core
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/puti-content-core/assets/admin-script.js/wp-content/plugins/puti-content-core/assets/admin-script.jsputi-content-core/assets/admin-script.js?ver=HTML / DOM Fingerprints
data-codeputicoco_PluginData/wp-json/puti-content-core/v1/script.js<puti-content