REST API Search Security & Risk Analysis

wordpress.org/plugins/rest-api-search

This adds the missing functionality of Search into the WordPress REST API.

20 active installs v1.4 PHP + WP 4.4+ Updated Jun 20, 2016
api-searchrest-api-searchrest-apisearch
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is REST API Search Safe to Use in 2026?

Generally Safe

Score 85/100

REST API Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the "rest-api-search" v1.4 plugin exhibits a strong security posture. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code analysis reveals a commendable lack of dangerous functions, SQL queries that are not prepared, unescaped output, file operations, and external HTTP requests. The complete absence of any known CVEs, let alone unpatched ones, suggests a history of secure development or prompt patching of any past issues.

The plugin demonstrates good practices by not bundling external libraries and showing no taint analysis findings, indicating a robust approach to handling data flow and preventing common injection vulnerabilities. The primary concern, if any, stems from the complete lack of any security checks (nonce or capability) being explicitly reported. While this might be a limitation of the analysis tool in detecting checks within its limited scope of entry points, it's an area to be mindful of if the plugin were to introduce new entry points in the future. Overall, for version 1.4, this plugin appears to be very secure and well-developed with no immediate critical or high-risk vulnerabilities identified.

Vulnerabilities
None known

REST API Search Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

REST API Search Release Timeline

v1.4Current
v1.3
v1.2
v1.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

REST API Search Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

REST API Search Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionrest_api_initrest-api-search.php:23
Maintenance & Trust

REST API Search Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJun 20, 2016
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

REST API Search Developer Profile

KCPT

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect REST API Search

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rest-api-search/css/search-filters.css/wp-content/plugins/rest-api-search/js/search-filters.js
Script Paths
/wp-content/plugins/rest-api-search/js/search-filters.js
Version Parameters
rest-api-search/css/search-filters.css?ver=rest-api-search/js/search-filters.js?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/rest-api-search/v1/search
FAQ

Frequently Asked Questions about REST API Search