
WP Custom REST API Generator Security & Risk Analysis
wordpress.org/plugins/wp-custom-rest-api-generatorWP Custom REST API Generator plugin enables the user to show/hide varied meta information of Posts in WordPress REST API.
Is WP Custom REST API Generator Safe to Use in 2026?
Generally Safe
Score 85/100WP Custom REST API Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wp-custom-rest-api-generator" v1.0.5 exhibits a generally positive security posture based on the static analysis provided. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate a good practice of using prepared statements for SQL queries and the presence of capability checks. The lack of dangerous functions, file operations, and external HTTP requests is also a strong positive indicator. However, a concerning aspect is the low percentage of properly escaped output (20%), suggesting potential vulnerabilities to cross-site scripting (XSS) if user-controlled data is displayed without adequate sanitization. The absence of taint analysis results and vulnerability history means we cannot assess risks from complex data flows or past security issues. Overall, the plugin is built with a minimal attack surface and some secure coding practices, but the insufficient output escaping is a notable weakness that could be exploited.
Key Concerns
- Low percentage of properly escaped output
WP Custom REST API Generator Security Vulnerabilities
WP Custom REST API Generator Code Analysis
Output Escaping
WP Custom REST API Generator Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP Custom REST API Generator Maintenance & Trust
Maintenance Signals
Community Trust
WP Custom REST API Generator Alternatives
Disable REST API
disable-json-api
Disable the use of the REST API on your website to site users. Now with User Role support!
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
REST API Log
wp-rest-api-log
WordPress plugin to log REST API requests and responses
WP API Menus
wp-api-menus
Extends WordPress WP REST API with new routes pointing to WordPress menus.
WP REST API – Pure Taxonomies
wp-rest-api-pure-taxonomies
This plugin include all available taxonomy attributes into the WordPress REST API (v2) without additional API requests.
WP Custom REST API Generator Developer Profile
2 plugins · 170 total installs
How We Detect WP Custom REST API Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-custom-rest-api-generator/includes/css/fontawesome-free-5.6.1-web/css/all.css/wp-content/plugins/wp-custom-rest-api-generator/includes/css/style.css/wp-content/plugins/wp-custom-rest-api-generator/includes/js/main.js/wp-content/plugins/wp-custom-rest-api-generator/includes/js/main.jswp-custom-rest-api-generator/includes/css/fontawesome-free-5.6.1-web/css/all.css?ver=wp-custom-rest-api-generator/includes/css/style.css?ver=wp-custom-rest-api-generator/includes/js/main.js?ver=HTML / DOM Fingerprints
wpcrag_get_author_metawpcrag_get_featured_imagewpcrag_get_post_metawpcrag_get_taxonomieswpcrag_get_post_typeswpcrag_get_all_posts/wp-json/wpcrag