RCP allow REST Security & Risk Analysis

wordpress.org/plugins/rcp-allow-rest

Allow RCP restricted posts to be delivered nevertheless when called from REST API

0 active installs v1.1 PHP + WP 3.0.1+ Updated Nov 22, 2017
commentsspam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RCP allow REST Safe to Use in 2026?

Generally Safe

Score 85/100

RCP allow REST has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "rcp-allow-rest" v1.1 plugin exhibits a strong security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are exposed. Furthermore, the code demonstrates good practices by not utilizing dangerous functions, performing file operations, making external HTTP requests, or bundling libraries. All SQL queries, if any were present, would be using prepared statements, and all output would be properly escaped. The absence of any taint analysis findings further strengthens this positive assessment.

The vulnerability history for this plugin is also remarkably clean, with no known CVEs recorded. This suggests a commitment to security by the developers, or at least a lack of discovered vulnerabilities to date. The plugin appears to have a very limited attack surface and a well-secured codebase. However, the lack of any identified capability checks or nonce checks, combined with a total of zero entry points, is unusual. While this suggests no *exposed* vulnerabilities, it could also indicate a plugin that doesn't perform significant actions or interact with WordPress in ways that would necessitate these checks.

In conclusion, the plugin appears to be highly secure based on the provided data, with no direct security risks identified in the code or its history. The strengths lie in its lack of attack surface and adherence to secure coding practices in the areas analyzed. The primary, albeit minor, point of observation is the complete absence of any capability or nonce checks, which, in conjunction with zero entry points, makes it hard to fully assess its potential interactions and how it handles sensitive data or actions if they were to be introduced or if the static analysis missed something. For its current state, the security is excellent.

Vulnerabilities
None known

RCP allow REST Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

RCP allow REST Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

RCP allow REST Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

RCP allow REST Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedincludes/class-rcp-allow-rest.php:139
actionadmin_enqueue_scriptsincludes/class-rcp-allow-rest.php:154
actionadmin_enqueue_scriptsincludes/class-rcp-allow-rest.php:155
actionwp_enqueue_scriptsincludes/class-rcp-allow-rest.php:170
actionwp_enqueue_scriptsincludes/class-rcp-allow-rest.php:171
actionplugins_loadedpublic/class-rcp-allow-rest-public.php:69
filterthe_contentpublic/class-rcp-allow-rest-public.php:107
Maintenance & Trust

RCP allow REST Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 22, 2017
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

RCP allow REST Developer Profile

termel

16 plugins · 810 total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RCP allow REST

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rcp-allow-rest/admin/css/rcp-allow-rest-admin.css/wp-content/plugins/rcp-allow-rest/admin/js/rcp-allow-rest-admin.js
Script Paths
/wp-content/plugins/rcp-allow-rest/admin/js/rcp-allow-rest-admin.js
Version Parameters
rcp-allow-rest-admin/css/rcp-allow-rest-admin.css?ver=rcp-allow-rest-admin/js/rcp-allow-rest-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about RCP allow REST