
Tutexp Rest Api Menu Security & Risk Analysis
wordpress.org/plugins/tutexp-rest-api-menuAdding menus endpoints on WP REST API v2
Is Tutexp Rest Api Menu Safe to Use in 2026?
Generally Safe
Score 100/100Tutexp Rest Api Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'tutexp-rest-api-menu' v1.0.0 exhibits a concerning security posture primarily due to its unprotected REST API routes. While the static analysis reveals no dangerous functions, SQL injection vulnerabilities, or output escaping issues, and there's no known vulnerability history, the presence of two REST API routes without permission callbacks represents a significant attack vector. This means any unauthenticated user could potentially interact with these endpoints, leading to unintended actions or information disclosure depending on their functionality.
The absence of nonce checks and capability checks on these routes further exacerbates the risk. The lack of taint analysis data is noted, but the existing findings are sufficient to warrant caution. The plugin demonstrates good practices in its use of prepared statements for SQL queries, but this strength is overshadowed by the critical oversight in securing its entry points. Users should be aware that while the plugin has no past vulnerabilities, the current design leaves it open to exploitation.
Key Concerns
- REST API routes without permission callbacks
- Total entry points without auth checks
- Missing capability checks
- Missing nonce checks
Tutexp Rest Api Menu Security Vulnerabilities
Tutexp Rest Api Menu Code Analysis
Tutexp Rest Api Menu Attack Surface
REST API Routes 2
WordPress Hooks 1
Maintenance & Trust
Tutexp Rest Api Menu Maintenance & Trust
Maintenance Signals
Community Trust
Tutexp Rest Api Menu Alternatives
WP-REST-API V2 Menus
wp-rest-api-v2-menus
Adding menus endpoints on WP REST API v2
WP API Menus
wp-api-menus
Extends WordPress WP REST API with new routes pointing to WordPress menus.
WP-REST-API Menus
wp-rest-api-menus
Adds menu endpoints to core WP REST API.
JSON REST API Subscriptions
json-rest-api-subscriptions
Enable subscriptions to posts, pages, and custom post types. Users can securely subscribe via simple API routes to created/updated/deleted content.
WP API (V2) WooCommerce endpoints
wp-api-v2-woocommerce-endpoints
Extends WordPress WP REST API (V2) with new endpoints pointing to WooCommerce page functions (is_shop, is_cart, is_checkout, is_account_page).
Tutexp Rest Api Menu Developer Profile
2 plugins · 0 total installs
How We Detect Tutexp Rest Api Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
tutexpmenu/v2/menustutexpmenu/v2/menus/(?P<id>[a-zA-Z_(-]+