wp-includes/rest-api/endpoints/class-wp-rest-plugins-controller.php:792Sanitizes the "plugin" parameter to be a proper plugin file with ".php" appended.
$filestringstring public function sanitize_plugin_param( $file ) { return plugin_basename( sanitize_text_field( $file . '.php' ) ); }Introduced in 5.5.0. Unchanged from 6.7.7 through 7.1.0.
Signature, return type and hooks compared across 5 parsed releases.
src/wp-includes/rest-api/endpoints/class-wp-rest-plugins-controller.php, and regenerated for each WordPress release so it tracks the code rather than a snapshot of it.