
WP REST Yoast Meta Security & Risk Analysis
wordpress.org/plugins/wp-rest-yoast-metaAdds meta tags as generated by Yoast SEO to the WP REST API. And adds a custom endpoint to retrieve all redirects as they are set in Yoast SEO Premium …
Is WP REST Yoast Meta Safe to Use in 2026?
Generally Safe
Score 92/100WP REST Yoast Meta has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-rest-yoast-meta plugin v2025.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices in areas like SQL query handling, with all queries utilizing prepared statements. Furthermore, all identified output operations are properly escaped, and the plugin does not engage in file operations or external HTTP requests. The absence of any recorded vulnerabilities or CVEs in its history is also a strong positive indicator.
However, significant concerns arise from the static analysis, specifically regarding the attack surface. The plugin exposes two REST API routes that lack permission callbacks, meaning they are unprotected and accessible without authentication. This presents a direct risk, as any unauthenticated user could potentially interact with these endpoints. The lack of any nonce checks across the analyzed code further exacerbates this issue, as it prevents the validation of the request's origin.
While the plugin's vulnerability history is clean, the current lack of authentication on its REST API routes is a critical oversight that could lead to future vulnerabilities. The absence of taint analysis results with critical or high severity is somewhat reassuring, but this could be a consequence of the limited attack surface analyzed in that specific regard. In conclusion, while the plugin adheres to good security practices in data handling and output, the unprotected REST API routes represent a substantial and immediate security weakness.
Key Concerns
- REST API routes without permission callbacks
- No nonce checks present
WP REST Yoast Meta Security Vulnerabilities
WP REST Yoast Meta Code Analysis
SQL Query Safety
Output Escaping
WP REST Yoast Meta Attack Surface
REST API Routes 2
WordPress Hooks 16
Maintenance & Trust
WP REST Yoast Meta Maintenance & Trust
Maintenance Signals
Community Trust
WP REST Yoast Meta Alternatives
WP REST Cache
wp-rest-cache
Enable caching of the WordPress REST API and auto-flush caches upon wp-admin editing.
REST API Log
wp-rest-api-log
WordPress plugin to log REST API requests and responses
REST API Toolbox
rest-api-toolbox
Allows tweaking of several REST API settings
WP API Menus
wp-api-menus
Extends WordPress WP REST API with new routes pointing to WordPress menus.
WP API SwaggerUI
wp-api-swaggerui
WordPress REST API with Swagger UI.
WP REST Yoast Meta Developer Profile
4 plugins · 12K total installs
How We Detect WP REST Yoast Meta
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-rest-yoast-meta/assets/css/admin-style.css/wp-content/plugins/wp-rest-yoast-meta/assets/js/admin-script.js/wp-content/plugins/wp-rest-yoast-meta/assets/js/admin-script.jswp-rest-yoast-meta/assets/css/admin-style.css?ver=wp-rest-yoast-meta/assets/js/admin-script.js?ver=HTML / DOM Fingerprints
/wp-json/wp-rest-yoast-meta/