Disable REST API for Real Security & Risk Analysis

wordpress.org/plugins/sar-disable-rest-api

Really prevents the REST API from handling requests (default) or require user to be logged in.

200 active installs v2.1.1 PHP + WP 4.7+ Updated Nov 14, 2019
apijsonrestrest-apiwp-json
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Disable REST API for Real Safe to Use in 2026?

Generally Safe

Score 85/100

Disable REST API for Real has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "sar-disable-rest-api" v2.1.1 plugin exhibits a remarkably strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, raw SQL queries, file operations, external HTTP requests, or unsanitized taint flows is highly commendable. This indicates a well-written and security-conscious codebase that actively avoids common web application vulnerabilities. The plugin also demonstrates good practices in output escaping and SQL query handling by exclusively using prepared statements. Furthermore, the vulnerability history being completely clear of any known CVEs, regardless of severity, strongly suggests a consistent track record of security. The overall picture is one of a highly secure and reliable plugin, with no immediate exploitable weaknesses detected in the code analysis or historical data.

Vulnerabilities
None known

Disable REST API for Real Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Disable REST API for Real Release Timeline

v2.1.1Current
v2.1
v2.0
v1.0
Code Analysis
Analyzed Mar 16, 2026

Disable REST API for Real Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Disable REST API for Real Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterinitsar-disable-rest-api.php:39
filterrest_jsonp_enabledsar-disable-rest-api.php:66
actiontemplate_redirectsar-disable-rest-api.php:74
filterrest_authentication_errorssar-disable-rest-api.php:90
filteradmin_initsar-disable-rest-api.php:106
Maintenance & Trust

Disable REST API for Real Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedNov 14, 2019
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings3
Active installs200
Developer Profile

Disable REST API for Real Developer Profile

Samuel Aguilera

14 plugins · 98K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Disable REST API for Real

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

REST Endpoints
/wp-json/
FAQ

Frequently Asked Questions about Disable REST API for Real