
WP REST API Custom Fields Security & Risk Analysis
wordpress.org/plugins/wp-rest-api-custom-fieldsShows Advanced Custom Field output to the WP REST API for posts, pages, taxonomies and users.
Is WP REST API Custom Fields Safe to Use in 2026?
Generally Safe
Score 85/100WP REST API Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the "wp-rest-api-custom-fields" v0.2 plugin exhibits a very strong security posture. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, or external HTTP requests is highly commendable. Furthermore, the plugin successfully avoids introducing a significant attack surface through AJAX handlers, REST API routes, shortcodes, or cron events. The taint analysis also reveals no concerning flows, indicating that data is likely handled securely within the plugin's scope.
The vulnerability history further reinforces this positive assessment, with zero recorded CVEs of any severity. This suggests a pattern of responsible development and a commitment to security from the maintainers. The lack of any common vulnerability types or recent issues points towards a mature and well-tested codebase.
In conclusion, this plugin appears to be exceptionally well-secured according to the provided data. The developers have adhered to best practices in all analyzed areas, and there is no historical or static analysis evidence to suggest any immediate security risks. It's important to note that this analysis is based solely on the provided data; a comprehensive security review would also consider dynamic analysis and potential edge cases not covered here.
WP REST API Custom Fields Security Vulnerabilities
WP REST API Custom Fields Code Analysis
WP REST API Custom Fields Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP REST API Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
WP REST API Custom Fields Alternatives
Disable REST API
disable-json-api
Disable the use of the REST API on your website to site users. Now with User Role support!
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
Disable WP REST API
disable-wp-rest-api
Disables the WP REST API for visitors not logged into WordPress.
WordPress REST API (Version 2)
rest-api
Access your site's data through an easy-to-use HTTP REST API. (Version 2)
WP REST API – OAuth 1.0a Server
rest-api-oauth1
Connect applications to your WordPress site without ever giving away your password.
WP REST API Custom Fields Developer Profile
2 plugins · 80 total installs
How We Detect WP REST API Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.