Restful Hello Dolly Security & Risk Analysis

wordpress.org/plugins/restful-hello-dolly

Do you think that all of core needs to have REST support? This is the plugin for you!

10 active installs v0.5 PHP + WP 4.4+ Updated Feb 6, 2016
apihello-dollyrestuseless
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Restful Hello Dolly Safe to Use in 2026?

Generally Safe

Score 85/100

Restful Hello Dolly has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'restful-hello-dolly' plugin exhibits a concerning security posture due to a single unprotected REST API route, representing a significant entry point for potential attackers. While the static analysis reveals no dangerous functions, raw SQL queries, unescaped output, file operations, or external HTTP requests, the absence of permission callbacks on the identified REST API route is a critical oversight. This means any user, regardless of their role or permissions, can potentially interact with this endpoint, leading to unauthorized actions or information disclosure. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign. However, this cannot entirely mitigate the immediate risk posed by the unprotected REST API. In conclusion, while the plugin demonstrates good practices in other areas of code security, the single, unauthenticated REST API endpoint presents a clear and present danger that needs immediate attention.

Key Concerns

  • Unprotected REST API route
Vulnerabilities
None known

Restful Hello Dolly Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Restful Hello Dolly Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface
1 unprotected

Restful Hello Dolly Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/restful-hello-dolly/v1/lyricrestful-hello-dolly.php:60
WordPress Hooks 2
actionrest_api_initrestful-hello-dolly.php:48
actioninitrestful-hello-dolly.php:85
Maintenance & Trust

Restful Hello Dolly Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedFeb 6, 2016
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Restful Hello Dolly Developer Profile

Jake Spurlock

8 plugins · 180 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Restful Hello Dolly

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

REST Endpoints
/restful-hello-dolly/v1/lyric
FAQ

Frequently Asked Questions about Restful Hello Dolly