
REST API – Head Tags Security & Risk Analysis
wordpress.org/plugins/rest-api-head-tagsAdds all the meta tags of the head section to WordPress REST API responses, including the ones generated by SEO plugins like Yoast or All in One SEO.
Is REST API – Head Tags Safe to Use in 2026?
Generally Safe
Score 85/100REST API – Head Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rest-api-head-tags" plugin version 1.2.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and has no known vulnerabilities in its history, suggesting a history of stable and secure development. It also avoids file operations and external HTTP requests, which are common sources of vulnerabilities.
However, significant concerns arise from the attack surface analysis. The plugin exposes a single AJAX handler that lacks any authentication or capability checks. This is a critical weakness, as it provides an unprotected entry point for malicious actors. While no critical or high severity taint flows were identified, the presence of two flows with unsanitized paths is concerning and could potentially lead to issues if the data handled by these flows is ever exploited. The low percentage of properly escaped output further exacerbates this risk, as it increases the likelihood of cross-site scripting (XSS) vulnerabilities.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL handling, the unprotected AJAX endpoint and the unescaped output represent substantial security risks that need immediate attention. The absence of nonce and capability checks on its single entry point is a major oversight that could be exploited.
Key Concerns
- AJAX handler without auth checks
- Low percentage of properly escaped output
- Flows with unsanitized paths
- No nonce checks on AJAX
- No capability checks
REST API – Head Tags Security Vulnerabilities
REST API – Head Tags Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
REST API – Head Tags Attack Surface
AJAX Handlers 1
WordPress Hooks 32
Maintenance & Trust
REST API – Head Tags Maintenance & Trust
Maintenance Signals
Community Trust
REST API – Head Tags Alternatives
IGen SEO API
igen-seo-api
Register Yoast SEO meta fields to make them accessible through REST API for reading and writing.
WP API Yoast SEO
wp-api-yoast-meta
Returns Yoast post or page metadata in a normal post or page request.
SEO Meta Description Updater
seo-meta-description-updater
A simple plugin to update SEO meta descriptions via the WordPress REST API.
SEO Rocket Integration
seo-rocket-integration
Publish SEO-optimized articles from SEO Rocket with automatic Yoast SEO and Rank Math metadata sync.
Publicator Helper
publicator-helper
Connecteur indispensable pour Publicator.fr - Générateur de contenus optimisés SEO avec IA.
REST API – Head Tags Developer Profile
1 plugin · 200 total installs
How We Detect REST API – Head Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rest-api-head-tags/admin/build/bundle.js/wp-content/plugins/rest-api-head-tags/admin/build/bundle.jsHTML / DOM Fingerprints
window.frontity.plugins.frontity_headtags.urlwindow.frontity.plugins.frontity_headtags.settings