
REST API Enabler Security & Risk Analysis
wordpress.org/plugins/rest-api-enablerEnable the WP REST API to work with custom post types, custom fields, and custom endpoints.
Is REST API Enabler Safe to Use in 2026?
Generally Safe
Score 85/100REST API Enabler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rest-api-enabler" plugin version 1.1.0 presents a mixed security posture. While the static analysis reports a complete absence of identifiable attack surface points like unprotected AJAX handlers, REST API routes without permission callbacks, shortcodes, or cron events, and no critical or high severity taint flows, these findings are overshadowed by significant concerns in how the code handles data. The plugin performs a single SQL query that is not prepared, posing a potential risk for SQL injection if any user-supplied data is incorporated into this query without proper sanitization. Furthermore, all seven detected output operations lack proper escaping, making it vulnerable to cross-site scripting (XSS) attacks. The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator. However, the internal code quality issues, particularly the unprepared SQL query and pervasive lack of output escaping, indicate a departure from secure coding best practices. Despite the lack of direct entry points for exploitation, the presence of these vulnerabilities means that if an attacker can find a way to inject data into the SQL query or trigger an unescaped output, significant damage could occur. The plugin's strengths lie in its limited attack surface and clean vulnerability history, but its weaknesses in data handling are critical security concerns that require immediate attention.
Key Concerns
- SQL queries not using prepared statements
- Output escaping is not properly implemented
REST API Enabler Security Vulnerabilities
REST API Enabler Code Analysis
SQL Query Safety
Output Escaping
REST API Enabler Attack Surface
WordPress Hooks 7
Maintenance & Trust
REST API Enabler Maintenance & Trust
Maintenance Signals
Community Trust
REST API Enabler Alternatives
Post Porter
post-porter
Post Porter enables seamless posts migration between WordPress sites via REST API, ensuring alignment with standard post principles.
WP REST API – Post Type Taxonomies
wp-rest-api-post-type-taxonomies
This plugin show all relations between existing post types and attached to them terms (taxonomies) in separate WordPress REST API (v2) endpoint.
Registration Honeypot
registration-honeypot
Plugin for stopping most spambot registrations via a simple honeypot method.
WP Rest Api V2 Multiple PostTypes
wp-api-multiple-posttype
Multiple Content type Query API for Wordpress Rest Api V2
Restaurant
restaurant
A restaurant and menu item manager for small restaurant sites, which can be extended for larger sites.
REST API Enabler Developer Profile
5 plugins · 71K total installs
How We Detect REST API Enabler
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rest-api-enabler/admin/css/rest-api-enabler-admin.css/wp-content/plugins/rest-api-enabler/admin/js/rest-api-enabler-admin.js/wp-content/plugins/rest-api-enabler/admin/js/rest-api-enabler-admin.jsrest-api-enabler/admin/css/rest-api-enabler-admin.css?ver=rest-api-enabler/admin/js/rest-api-enabler-admin.js?ver=HTML / DOM Fingerprints
rest-api-enabler-settingsrae-settings-tabrae-post-types-settingsrae-post-meta-settingsdata-setting-name