WP REST API Filter Fields Security & Risk Analysis

wordpress.org/plugins/wp-rest-api-filter-fields

Extends the functionality of [WP REST API]. Allows you to request only certain fields.

10 active installs v1 PHP + WP 3.9+ Updated Unknown
apijsonrestrest-api
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP REST API Filter Fields Safe to Use in 2026?

Generally Safe

Score 100/100

WP REST API Filter Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the provided static analysis and vulnerability history, the "wp-rest-api-filter-fields" v1 plugin appears to have a strong security posture. The absence of dangerous functions, reliance on prepared statements for SQL queries, and proper output escaping indicate good coding practices. Furthermore, the lack of any recorded CVEs or known vulnerabilities in its history suggests a well-maintained and secure plugin over time.

The static analysis reveals no discernible attack surface in terms of AJAX handlers, REST API routes, shortcodes, or cron events that are not adequately protected. Taint analysis also shows no critical or high-severity flows, reinforcing the impression of secure code. This comprehensive lack of vulnerabilities and potential entry points makes the plugin highly unlikely to be a source of common security exploits.

While the plugin demonstrates excellent security hygiene, the complete absence of entry points (AJAX, REST API, shortcodes, cron) might indicate a limited functionality or that its purpose is served entirely through other means not captured in this specific analysis. However, within the scope of the provided data, the plugin exhibits a robust security profile with no identified weaknesses.

Vulnerabilities
None known

WP REST API Filter Fields Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP REST API Filter Fields Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP REST API Filter Fields Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterjson_prepare_postplugin.php:10
filterjson_prepare_taxonomyplugin.php:23
filterjson_prepare_commentplugin.php:36
filterjson_prepare_posttrunk\plugin.php:10
filterjson_prepare_taxonomytrunk\plugin.php:23
filterjson_prepare_commenttrunk\plugin.php:36
Maintenance & Trust

WP REST API Filter Fields Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating80/100
Number of ratings1
Active installs10
Developer Profile

WP REST API Filter Fields Developer Profile

Formcrafts

8 plugins · 11K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
823 days
View full developer profile
Detection Fingerprints

How We Detect WP REST API Filter Fields

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP REST API Filter Fields