WP REST API Meta Endpoints Security & Risk Analysis

wordpress.org/plugins/rest-api-meta-endpoints

WP REST API companion plugin for post meta endpoints.

1K active installs v0.1.0 PHP + WP 4.4+ Updated Feb 9, 2016
apijsonrestrest-api
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP REST API Meta Endpoints Safe to Use in 2026?

Generally Safe

Score 85/100

WP REST API Meta Endpoints has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'rest-api-meta-endpoints' plugin v0.1.0 exhibits an excellent security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events indicates a minimal attack surface. Crucially, all analyzed code signals, including SQL queries, output escaping, file operations, and external HTTP requests, demonstrate adherence to secure coding practices. The lack of any recorded vulnerabilities, including CVEs, further reinforces its current secure state.

While the current analysis presents a very positive outlook, it's important to acknowledge the version being analyzed is 0.1.0, which is an early release. This typically means the plugin is less mature and may not have undergone extensive real-world testing or scrutiny that more established plugins benefit from. The absence of specific checks like nonce or capability checks (though not strictly required given the zero entry points) could become a concern in future versions if new entry points are introduced without them. Overall, this version appears robust, but ongoing vigilance for future updates is recommended.

Vulnerabilities
None known

WP REST API Meta Endpoints Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP REST API Meta Endpoints Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP REST API Meta Endpoints Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionrest_api_initplugin.php:32
Maintenance & Trust

WP REST API Meta Endpoints Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedFeb 9, 2016
PHP min version
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

WP REST API Meta Endpoints Developer Profile

Daniel Bachhuber

9 plugins · 51K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP REST API Meta Endpoints

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rest-api-meta-endpoints/lib/class-wp-rest-meta-controller.php/wp-content/plugins/rest-api-meta-endpoints/lib/class-wp-rest-meta-posts-controller.php

HTML / DOM Fingerprints

REST Endpoints
/wp-json/wp/v2/meta/wp-json/wp/v2/<post_type>/meta
FAQ

Frequently Asked Questions about WP REST API Meta Endpoints