
REST API Log Security & Risk Analysis
wordpress.org/plugins/wp-rest-api-logWordPress plugin to log REST API requests and responses
Is REST API Log Safe to Use in 2026?
Generally Safe
Score 92/100REST API Log has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-rest-api-log" plugin v1.7.0 demonstrates a mixed security posture. On the positive side, the plugin shows strong adherence to secure coding practices with a high percentage of properly escaped outputs and a majority of SQL queries utilizing prepared statements. The absence of dangerous functions, file operations, external HTTP requests, and known vulnerability history are also significant strengths, suggesting a generally well-maintained codebase. However, the presence of one unprotected AJAX handler stands out as a notable concern. While the total attack surface is small, this single unauthenticated entry point could potentially be exploited if it handles user-supplied data without proper validation or sanitization, despite the lack of critical taint analysis findings in the static scan. The plugin's vulnerability history being clean is encouraging, but it doesn't entirely negate the risk posed by the unprotected AJAX handler. Overall, the plugin has a good foundation for security, but the unprotected AJAX endpoint requires careful review and potentially patching to mitigate any latent risks.
Key Concerns
- Unprotected AJAX handler found
REST API Log Security Vulnerabilities
REST API Log Code Analysis
SQL Query Safety
Output Escaping
REST API Log Attack Surface
AJAX Handlers 1
WordPress Hooks 41
Scheduled Events 1
Maintenance & Trust
REST API Log Maintenance & Trust
Maintenance Signals
Community Trust
REST API Log Alternatives
WP API Menus
wp-api-menus
Extends WordPress WP REST API with new routes pointing to WordPress menus.
WP-REST-API Menus
wp-rest-api-menus
Adds menu endpoints to core WP REST API.
API Log Pro
api-log-pro
A simple plugin to log WordPress Rest API Requests.
WP API (V2) WooCommerce endpoints
wp-api-v2-woocommerce-endpoints
Extends WordPress WP REST API (V2) with new endpoints pointing to WooCommerce page functions (is_shop, is_cart, is_checkout, is_account_page).
WP API Options
wp-rest-api-options
Extends WordPress WP REST API with new routes pointing to WordPress options.
REST API Log Developer Profile
8 plugins · 8K total installs
How We Detect REST API Log
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-rest-api-log/admin/js/wp-rest-api-log-admin.js/wp-content/plugins/wp-rest-api-log/admin/js/wp-rest-api-log-admin.jswp-rest-api-log/admin/js/wp-rest-api-log-admin.js?ver=HTML / DOM Fingerprints
wp_rest_api_log_start/wp-json/wp-rest-api-log/v1/