
SMNTCS Disable REST API User Endpoints Security & Risk Analysis
wordpress.org/plugins/smntcs-disable-rest-api-user-endpointsDisable the REST API user endpoints due to obscure user slugs.
Is SMNTCS Disable REST API User Endpoints Safe to Use in 2026?
Generally Safe
Score 92/100SMNTCS Disable REST API User Endpoints has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "smntcs-disable-rest-api-user-endpoints" plugin, version 2.4, exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any identified attack surface, dangerous functions, direct SQL queries, unescaped output, file operations, external HTTP requests, or nonces is a significant strength. The plugin's code also demonstrates meticulous attention to security by relying entirely on prepared statements for any potential SQL interactions (though none were found). The taint analysis further reinforces this, revealing no potentially unsanitized data flows, indicating robust input handling. The vulnerability history, with zero recorded CVEs across all severities and no recent disclosures, suggests a history of responsible development and maintenance.
However, a notable concern arises from the complete lack of capability checks and nonce checks. While the plugin's stated purpose (disabling REST API user endpoints) might imply it doesn't require direct user interaction or permissioned actions, this absence of standard security mechanisms could be a vulnerability if the plugin's functionality were ever to expand or be misinterpreted. The plugin appears to be designed for a very specific, low-risk function with no direct user interaction, which is commendable. The overall security is excellent for its current, narrowly defined scope.
Key Concerns
- Missing capability checks
- Missing nonce checks
SMNTCS Disable REST API User Endpoints Security Vulnerabilities
SMNTCS Disable REST API User Endpoints Code Analysis
SMNTCS Disable REST API User Endpoints Attack Surface
WordPress Hooks 1
Maintenance & Trust
SMNTCS Disable REST API User Endpoints Maintenance & Trust
Maintenance Signals
Community Trust
SMNTCS Disable REST API User Endpoints Alternatives
Custom API for WP
custom-api-for-wp
Connect WordPress with External APIs and create no-code custom WordPress REST API endpoints to interact with the WordPress database to perform SQL ope …
REST API Custom Fields
rest-api-custom-fields
This plugin enhances Wordpress REST API v2 responses about metadata
WPControl – The Easiest Optimization Plugin for WordPress
wpcontrol
The easiest way to improve your website's security, performance, and user experience.
Ajax Load More: REST API
ajax-load-more-rest-api
An Ajax Load More extension that adds compatibility for the WP REST API.
WP REST API Key Authentication
rest-api-key-authentication
A simple plugin to add API key-based authentication to the WordPress REST API. Manage multiple API keys and secure your REST API endpoints.
SMNTCS Disable REST API User Endpoints Developer Profile
20 plugins · 20K total installs
How We Detect SMNTCS Disable REST API User Endpoints
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smntcs-disable-rest-api-user-endpoints/smntcs-disable-rest-api-endpoints.phpsmntcs-disable-rest-api-user-endpoints/smntcs-disable-rest-api-endpoints.php?ver=2.4HTML / DOM Fingerprints
/wp/v2/users/wp/v2/users/(?P<id>[\d]+)