
WP REST API Controller Security & Risk Analysis
wordpress.org/plugins/wp-rest-api-controllerEnable a UI to toggle visibility and customize properties in WP REST API requests.
Is WP REST API Controller Safe to Use in 2026?
Generally Safe
Score 85/100WP REST API Controller has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-rest-api-controller" v2.1.2 plugin exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that present an attack surface, and importantly, none are unprotected. The code also shows a commendable lack of dangerous functions, file operations, and external HTTP requests. Furthermore, the high percentage of SQL queries using prepared statements and properly escaped output indicates good development practices for preventing common vulnerabilities.
The vulnerability history of this plugin is also a significant positive indicator, with zero recorded CVEs. This suggests a mature and well-maintained codebase, or at least one that has not historically been a target for significant security flaws. The absence of taint analysis findings further reinforces the impression of a secure plugin.
In conclusion, this plugin appears to be very secure, with a minimal attack surface and robust coding practices. The lack of vulnerabilities in its history is a strong testament to its safety. While the capability checks being absent might be a minor point of consideration in certain complex scenarios, the overall lack of any identified vulnerabilities or exploitable entry points makes this plugin a low-risk option.
WP REST API Controller Security Vulnerabilities
WP REST API Controller Code Analysis
SQL Query Safety
Output Escaping
WP REST API Controller Attack Surface
WordPress Hooks 11
Maintenance & Trust
WP REST API Controller Maintenance & Trust
Maintenance Signals
Community Trust
WP REST API Controller Alternatives
REST API Manager For ACF
rest-api-manager-for-acf
Custom REST API endpoint plugin to return ACF fields, post meta (selected keys), or a mixed object. Fully configurable from the admin settings page.
WPGet API – Connect to any external REST API
wpgetapi
Connect any REST API to WordPress. WPGet API enables easy API integration, allowing you to display API data without any code.
REST API Meta Support
rest-api-meta-support
Stores meta data (i.e plugin settings) from the meta field of a WP REST API posts or pages POST creation call in the created page or post meta data.
SMNTCS Disable REST API User Endpoints
smntcs-disable-rest-api-user-endpoints
Disable the REST API user endpoints due to obscure user slugs.
Custom API for WP
custom-api-for-wp
Connect WordPress with External APIs and create no-code custom WordPress REST API endpoints to interact with the WordPress database to perform SQL ope …
WP REST API Controller Developer Profile
15 plugins · 136K total installs
How We Detect WP REST API Controller
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
wp-rest-api-controller/style.css?ver=wp-rest-api-controller/script.js?ver=HTML / DOM Fingerprints
wpRestApiSettings/wp-json/wp-rest-api-controller/v1/settings