Custom API for WP
View on WordPress.orgScores higher than 41% of indexed plugins
About
Connect WordPress with External APIs and create no-code custom WordPress REST API endpoints to interact with the WordPress database to perform SQL ope …
Security History
What It Does
Custom API for WP lets site owners build no-code REST API endpoints for reading and writing to the WordPress database, and it also connects WordPress to external APIs for pushing and pulling data. In practice, it turns a WordPress install into a backend service that mobile apps, CRMs, and other platforms can talk to without writing PHP.
Who It's For
This is a good fit for developers or technical marketers running headless WordPress setups, mobile app backends, or inventory and order workflows where the default REST API does not cover the data shape needed. It is also useful for small agencies that need to spin up custom endpoints for clients without building a bespoke plugin each time.
Who Should Skip It
If you only need to expose standard WordPress content (posts, pages, users, custom post types) to a frontend, the core REST API or WPGraphQL already covers that with far more community vetting. Non-technical site owners should also skip this, because configuring custom SQL-backed endpoints still requires a clear understanding of what data is being exposed and to whom.
The Bottom Line
Custom API for WP fills a real gap for no-code custom REST endpoints and SQL-backed reads and writes, and its maintenance and rating signals are genuinely strong. The main caveat is the tiny install base and the absence of any public support history, so you are trusting a single developer with very little community oversight. Try it on a staging site first, and have a backup plan if the project goes quiet.
Related Plugins
Choose WPGraphQL when your frontend is a JavaScript framework that prefers GraphQL queries over REST, and you mainly need to read WordPress content rather than expose custom SQL operations.
Pick this when your main concern is securing existing REST endpoints with token-based authentication rather than building new custom endpoints.
This is the opposite use case: choose it when you want to lock down the REST API entirely on a site that does not need external access.
WPGet API is a closer functional match, so pick it instead if your priority is consuming data from external REST APIs in WordPress rather than exposing WordPress data to outside systems.