[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fguuW1yC1XeeCSziE0N8fNpjZ5EL_Uw-1z9Rw4J4Zh-k":3,"$fkS__KAhdZ02_tkIt1WhytC70ZBu3j7Ih0ZzviGb2xnY":131,"$frug7xkKPGtoGLEBIZTTyrhgquihKrUQhIBx6y-wZfGU":136},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":37,"analysis":26,"fingerprints":26},"maxtdesign-rest-api-control","MaxtDesign REST API Control","1.0.5","MaxtDesign","https:\u002F\u002Fprofiles.wordpress.org\u002Fslaacr\u002F","\u003Cp>\u003Cstrong>MaxtDesign REST API Control\u003C\u002Fstrong> gives you complete control over who can access your WordPress REST API and which endpoints are available.\u003C\u002Fp>\n\u003Cp>By default, WordPress exposes a REST API to the public, which can reveal usernames, post data, and site structure to anyone. This plugin lets you lock down the REST API for unauthenticated visitors while keeping it fully functional for logged-in users and the plugins that need it.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>One-click disable\u003C\u002Fstrong> — Block all REST API access for unauthenticated users with a single toggle.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Endpoint whitelisting\u003C\u002Fstrong> — Auto-discovers all registered REST API endpoints and lets you whitelist specific ones, even when the API is disabled.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Per-role access control\u003C\u002Fstrong> — Restrict REST API access for specific user roles with individual endpoint whitelists.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart defaults\u003C\u002Fstrong> — Automatically detects Contact Form 7 and WooCommerce and whitelists their required endpoints on activation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero frontend footprint\u003C\u002Fstrong> — No CSS, JavaScript, or HTTP requests are added to your frontend. Ever.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight\u003C\u002Fstrong> — No database queries on frontend requests. Uses a single autoloaded option.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Import\u002FExport\u003C\u002Fstrong> — Transfer settings between sites with JSON export and import.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean uninstall\u003C\u002Fstrong> — Removes all plugin data when deleted. Leaves no trace.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How It Works\u003C\u002Fh4>\n\u003Cp>The plugin uses the \u003Ccode>rest_authentication_errors\u003C\u002Fcode> filter — the correct, modern WordPress approach — to intercept REST API requests early in the lifecycle, before any endpoint logic executes. This means blocked requests have virtually zero performance impact.\u003C\u002Fp>\n\u003Ch4>Built for Performance\u003C\u002Fh4>\n\u003Cp>This plugin follows the MaxtDesign performance-first philosophy:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Zero frontend asset loading (no CSS, no JS, no HTTP requests)\u003C\u002Fli>\n\u003Cli>Admin assets load only on the plugin’s own settings page\u003C\u002Fli>\n\u003Cli>Single autoloaded database option — no extra queries\u003C\u002Fli>\n\u003Cli>Filter fires before endpoint logic — blocked requests are fast\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>This plugin makes no external HTTP requests, sets no cookies, loads no third-party scripts, and collects no analytics. It does not track usage and never “calls home.” It stores a single settings option (\u003Ccode>mdra_settings\u003C\u002Fcode>) in your database and nothing else; that option is removed when you delete the plugin. No personal or visitor data is processed or transmitted.\u003C\u002Fp>\n","Full control over your WordPress REST API. Block, restrict, or whitelist endpoints per user role. Lightweight, fast, zero frontend footprint.",0,92,"2026-06-18T15:53:00.000Z","7.0.2","6.4","8.2",[18,19,20,21,22],"api-control","disable-rest-api","json-api","rest-api","security","https:\u002F\u002Fmaxtdesign.com\u002Fplugins\u002Fdisable-rest-api","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmaxtdesign-rest-api-control.1.0.5.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":33,"avg_security_score":25,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"slaacr",5,150,30,94,"2026-08-26T10:10:42.335Z",[38,61,78,96,114],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":48,"num_ratings":49,"last_updated":50,"tested_up_to":51,"requires_at_least":52,"requires_php":53,"tags":54,"homepage":58,"download_link":59,"security_score":60,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"wpcontrol","WPControl – The Easiest Optimization Plugin for WordPress","1.0.1","Syed Balkhi","https:\u002F\u002Fprofiles.wordpress.org\u002Fsmub\u002F","\u003Cp>WPControl is the ultimate way to clean up your WordPress site.\u003C\u002Fp>\n\u003Cp>With over 20 built-in optimizations, WPControl allows you to easily enable and disable WordPress Core features, letting you remove those features that you don’t use from the dashboard you and your users see.\u003C\u002Fp>\n\u003Cp>Simply put, WPControl is the ultimate plugin that you need to control your website. With our single plugin, you can remove the need to have plugins for things like:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disabling emails\u003C\u002Fli>\n\u003Cli>Disabling comments\u003C\u002Fli>\n\u003Cli>Disabling the WordPress REST API\u003C\u002Fli>\n\u003Cli>and so much more\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All in a single, easy to use plugin that helps boost both the performance and security of your WordPress install.\u003C\u002Fp>\n\u003Cp>WPControl is designed for simplicity first, made by the same \u003Ca href=\"https:\u002F\u002Fwpbeginner.com\u002F\" title=\"WPBeginner\" rel=\"friend nofollow ugc\">WPBeginner team\u003C\u002Fa> that makes your favorite WordPress tutorials.\u003C\u002Fp>\n\u003Cp>Our plugin is used by the plugin authors behind many of your favorite WordPress plugins including \u003Ca href=\"https:\u002F\u002Fwww.monsterinsights.com\u002F\" title=\"MonsterInsights\" rel=\"friend nofollow ugc\">MonsterInsights\u003C\u002Fa> , \u003Ca href=\"https:\u002F\u002Fwpforms.com\u002F\" title=\"WPForms\" rel=\"friend nofollow ugc\">WPForms\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Faioseo.com\u002F\" title=\"AIOSEO\" rel=\"friend nofollow ugc\">AIOSEO\u003C\u002Fa>  and more.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>Simple, yet powerful. I love that I can easily disable all of the features of WordPress I’m not using in a single plugin. It makes new site setup a breeze!\u003Cbr \u002F>\n  \u003Cbr \u002F>\n  Chris Christoff\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>At WPControl, we found that there are many unused features of WordPress that make it a hassle sometimes or we just don’t need. There are tons of plugins already out there that will disable a specific feature. But taking the time and energy to optimize all of them was too much. We made just one plugin that has the features of many so you can have a one stop shop for disabling unused features of WordPress.\u003C\u002Fp>\n\u003Cp>Unlike other methods of disabling features, WPControl allows you to disable many features with just a few clicks (no need to hire a developer).\u003C\u002Fp>\n\u003Ch4>Settings Include\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Comments\u003C\u002Fstrong> – You can disable comments site wide or on specific post types such as posts, pages, and media.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Gutenberg\u003C\u002Fstrong> – Disables the Gutenberg block editor and reverts it the Classic Editor\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable “Try Gutenberg” Nag\u003C\u002Fstrong> – Removes the annoying admin notice that keeps nagging you to try Gutenberg\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Shortlinks\u003C\u002Fstrong> – The tag is auto generated by WordPress and is used to create shortlinks. If you are already using pretty permalinks, such as the PrettyLinks plugin. Then there is no need for this unnecessary tag.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable RSD Link\u003C\u002Fstrong> – RSD Links are used by blog clients and some 3rd parties that utilize XML-RPC requests. If you edit your site through your browser, then you do not need it. Most of the time, it is just unnecessary code.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Remove XFN Profile Link\u003C\u002Fstrong> – The XFN Profile Link is used to add semantic data to links to be used by browsers to assign relationships between profiles. Basically it tells browsers that the site contains links that use XFN Specification\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable wlwmanifest Link\u003C\u002Fstrong> – The wlwmanifest link is used by Windows Live Writer. If you don’t use Windows Live Writer then disable the link as it is unnecessary code.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Links to Previous and Next Post\u003C\u002Fstrong> – If your site is not a blog and is used as a CMS, then this feature will remove the previous and next post links in your WordPress theme.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable XML-RPC Pingback\u003C\u002Fstrong> – Removes XML-RPC method to prevent abuse of site’s pingback while you can use the rest of the XML-RPC Pingback method.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Gravatar\u003C\u002Fstrong> – Blocks users WordPress from getting user Gravatar from their email to add privacy for the users or prevent inappropriate avatars.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Rest API\u003C\u002Fstrong> – Disables the REST-API to prevent abuse of Rest\u002FJSON API.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Hide Login Errors\u003C\u002Fstrong> – An attacker can find the authors login using a similar request as mysite.com\u002F?author=1.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Remove HTML comments\u003C\u002Fstrong> – Removes HTML comments in source code to add a layer of defense from attackers trying to find the version of plugins.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Remove Meta Generator\u003C\u002Fstrong> – This meta tag allows attackers to see the version of WordPress, it serves no useful purpose.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Right Click\u003C\u002Fstrong> – You can disable the ability to right click on your site, or just specific things like posts, pages, media, front page, and even have the ability to show an alert to the user that right click is disabled.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Admin Notices\u003C\u002Fstrong> – You can disable all admin notices that appear in the admin settings page.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable New User Emails\u003C\u002Fstrong> – Stops WordPress from sending new user notification emails to admin.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Search\u003C\u002Fstrong> – Disable the front-end search bar in WordPress.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Lazy Loading\u003C\u002Fstrong> – Removes the lazy loading functionality that was added in WordPress 5.3.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Hide Admin Toolbar\u003C\u002Fstrong> – Hides the admin toolbar when the admin is on the front-end\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Dashboard Widgets\u003C\u002Fstrong> – Gives you the option to disable whichever default dashboard widgets you want.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>After reading this feature list, you can probably imagine why WPControl is the best disable plugin for WordPress.\u003C\u002Fp>\n\u003Cp>Give WPControl a try today!\u003C\u002Fp>\n\u003Ch4>Credits\u003C\u002Fh4>\n\u003Cp>This plugin is created by Zain Balkhi of the \u003Ca href=\"https:\u002F\u002Fwpbeginner.com\u002F\" title=\"WPBeginner\" rel=\"friend nofollow ugc\">WPBeginner team\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>What’s Next\u003C\u002Fh4>\n\u003Cp>If you like this plugin, then consider checking out our other projects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.monsterinsights.com\u002F\" title=\"MonsterInsights\" rel=\"friend nofollow ugc\">MonsterInsights\u003C\u002Fa> – Best Google Analytics plugin for WordPress\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Foptinmonster.com\u002F\" title=\"OptinMonster\" rel=\"friend nofollow ugc\">OptinMonster\u003C\u002Fa> – Get More Email Subscribers\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpforms.com\u002F\" title=\"WPForms\" rel=\"friend nofollow ugc\">WPForms\u003C\u002Fa> – Best WordPress Contact Form Plugin\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Faioseo.com\u002F\" title=\"AIOSEO\" rel=\"friend nofollow ugc\">AIOSEO\u003C\u002Fa> – The original WordPress SEO plugin to help you rank higher in search results (trusted by over 2 million sites)\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.seedprod.com\u002F\" title=\"SeedProd\" rel=\"friend nofollow ugc\">SeedProd\u003C\u002Fa> – Most popular coming soon & maintenance mode plugin for WordPress\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpmailsmtp.com\u002F\" title=\"WP Mail SMTP\" rel=\"friend nofollow ugc\">WP Mail SMTP\u003C\u002Fa> – Improve email deliverability for your contact form with the most popular SMTP plugin for WordPress\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Frafflepress.com\u002F\" title=\"RafflePress\" rel=\"friend nofollow ugc\">RafflePress\u003C\u002Fa> – Best WordPress giveaway and contest plugin to grow traffic and social followers\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fsmashballoon.com\u002F\" title=\"Smash Balloon\" rel=\"friend nofollow ugc\">Smash Balloon\u003C\u002Fa> – #1 social feeds plugin for WordPress – display social media content in WordPress without code\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpushengage.com\u002F\" title=\"PushEngage\" rel=\"friend nofollow ugc\">PushEngage\u003C\u002Fa> – Connect with visitors after they leave your website with the leading web push notification plugin\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Ftrustpulse.com\u002F\" title=\"TrustPulse\" rel=\"friend nofollow ugc\">TrustPulse\u003C\u002Fa> – Add real-time social proof notifications to boost your store conversions by up to 15%\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin would not be possible without the help and support of \u003Ca href=\"http:\u002F\u002Fwww.wpbeginner.com\u002F\" title=\"WPBeginner\" rel=\"friend nofollow ugc\">WPBeginner\u003C\u002Fa>, the largest WordPress resource site. You can learn from our \u003Ca href=\"http:\u002F\u002Fwww.wpbeginner.com\u002Fcategory\u002Fwp-tutorials\u002F\" title=\"WordPress Tutorials\" rel=\"friend nofollow ugc\">free WordPress Tutorials\u003C\u002Fa> like \u003Ca href=\"http:\u002F\u002Fwww.wpbeginner.com\u002Fhow-to-install-wordpress\u002F\" title=\"How to Install WordPress - Step by Step\" rel=\"friend nofollow ugc\">how to install WordPress\u003C\u002Fa>, \u003Ca href=\"http:\u002F\u002Fwww.wpbeginner.com\u002Fwordpress-hosting\u002F\" title=\"How to choose the best WordPress hosting\" rel=\"friend nofollow ugc\">choose the best WordPress hosting\u003C\u002Fa>, \u003Ca href=\"http:\u002F\u002Fwww.wpbeginner.com\u002Fglossary\u002F\" title=\"WordPress Glossary Terms for Beginners\" rel=\"friend nofollow ugc\">WordPress glossary\u003C\u002Fa>, and more.\u003C\u002Fp>\n\u003Cp>You can also learn about other \u003Ca href=\"http:\u002F\u002Fwww.wpbeginner.com\u002Fcategory\u002Fplugins\u002F\" title=\"Best WordPress Plugins\" rel=\"friend nofollow ugc\">best WordPress plugins\u003C\u002Fa>.\u003C\u002Fp>\n","The easiest way to improve your website's security, performance, and user experience.",200,4625,90,2,"2022-04-18T21:12:00.000Z","5.9.13","3.8.0","5.6",[55,56,19,57,22],"disable-comments","disable-gutenberg","performance","https:\u002F\u002Fwww.wpcontrol.com\u002F?utm_source=liteplugin&utm_medium=pluginheader&utm_campaign=pluginurl&utm_content=7%2E0%2E0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpcontrol.1.0.1.zip",85,{"slug":62,"name":63,"version":64,"author":65,"author_profile":66,"description":67,"short_description":68,"active_installs":25,"downloaded":69,"rating":11,"num_ratings":11,"last_updated":70,"tested_up_to":14,"requires_at_least":71,"requires_php":72,"tags":73,"homepage":76,"download_link":77,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"turn-off-rest-api","Turn Off REST API","1.1.1","ksym04","https:\u002F\u002Fprofiles.wordpress.org\u002Fksym04\u002F","\u003Cp>\u003Cstrong>Turn Off REST API\u003C\u002Fstrong> is a lightweight WordPress security plugin that disables the WordPress REST API for visitors who are not logged in. Anonymous requests to your \u003Ccode>\u002Fwp-json\u003C\u002Fcode> endpoints receive an authentication error instead of your site data, while logged in users, your theme, and your plugins keep working normally.\u003C\u002Fp>\n\u003Cp>By default WordPress exposes a large amount of information through the REST API, including your list of user accounts and usernames, published content, and details about your site. For most sites that open, unauthenticated access is unnecessary and only widens the attack surface for user enumeration and content scraping. Turn Off REST API closes the WordPress REST API to the public in one click, then gives you a clear settings screen to reopen only the specific REST API routes you actually need.\u003C\u002Fp>\n\u003Ch4>Why turn off the WordPress REST API?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Stop anonymous user enumeration through \u003Ccode>\u002Fwp-json\u002Fwp\u002Fv2\u002Fusers\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>Reduce your attack surface against REST API based exploits and bots.\u003C\u002Fli>\n\u003Cli>Keep your content and site data from being scraped through the public API.\u003C\u002Fli>\n\u003Cli>Stay in control with a per route allow list instead of an all or nothing switch.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What it does\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Returns an authentication error for unauthenticated REST API requests.\u003C\u002Fli>\n\u003Cli>Optionally removes the REST API discovery links and headers from your page source.\u003C\u002Fli>\n\u003Cli>Lets you build an allow list of routes that should stay public (for example a contact form or a specific integration).\u003C\u002Fli>\n\u003Cli>Adds a Site Health check so the restriction is clearly explained and never mistaken for a fault.\u003C\u002Fli>\n\u003Cli>Keeps the admin area, the block editor, and logged in functionality fully working.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Built for control, not breakage\u003C\u002Fh4>\n\u003Cp>Some security plugins disable the REST API completely and break the block editor or third party integrations in the process. Turn Off REST API only blocks unauthenticated access, and the per route allow list means you can whitelist exactly the endpoints a service needs without opening the whole API back up.\u003C\u002Fp>\n\u003Ch4>Developer friendly\u003C\u002Fh4>\n\u003Cp>The access decision runs through the \u003Ccode>tora_grant_rest_api\u003C\u002Fcode> filter, so developers can extend or override the logic for custom roles, application passwords, or trusted requests.\u003C\u002Fp>\n","Disable the WordPress REST API for logged out visitors and lock down your \u002Fwp-json endpoints, with a per route allow list so you stay in control.",3050,"2026-06-27T19:25:00.000Z","4.7","7.4",[19,74,21,22,75],"json","wp-json","https:\u002F\u002Fwww.dopethemes.com\u002Fdownloads\u002Fturn-off-rest-api\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fturn-off-rest-api.1.1.1.zip",{"slug":79,"name":80,"version":81,"author":82,"author_profile":83,"description":84,"short_description":85,"active_installs":11,"downloaded":86,"rating":11,"num_ratings":11,"last_updated":87,"tested_up_to":88,"requires_at_least":89,"requires_php":72,"tags":90,"homepage":93,"download_link":94,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":95},"rest-armor-security","RestArmor Security","2.3","Md. Rakib Ullah","https:\u002F\u002Fprofiles.wordpress.org\u002Frakib417\u002F","\u003Cp>RestArmor Security is a “Plug & Play” security suite that hardens your WordPress site instantly upon activation. No complex setup required.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Disable XML-RPC:\u003C\u002Fstrong> Blocks XML-RPC attacks and Pingbacks.\u003Cbr \u002F>\n* \u003Cstrong>Block REST API:\u003C\u002Fstrong> Restricts API access to logged-in users only.\u003Cbr \u002F>\n* \u003Cstrong>Stop User Enumeration:\u003C\u002Fstrong> Blocks bot scans for \u002F?author=1.\u003Cbr \u002F>\n* \u003Cstrong>Hide WP Version:\u003C\u002Fstrong> Removes version number from source code.\u003Cbr \u002F>\n* \u003Cstrong>Admin Indicator:\u003C\u002Fstrong> Shows security status in the admin bar.\u003C\u002Fp>\n","Advanced security suite. Blocks REST API, disables XML-RPC, prevents user enumeration, and secures endpoints.",160,"2026-02-11T12:35:00.000Z","6.9.4","5.8",[19,91,21,22,92],"protection","xml-rpc","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Frest-armor-security.2.3.zip","2026-04-06T09:54:40.288Z",{"slug":97,"name":98,"version":99,"author":100,"author_profile":101,"description":102,"short_description":103,"active_installs":11,"downloaded":104,"rating":25,"num_ratings":105,"last_updated":106,"tested_up_to":14,"requires_at_least":107,"requires_php":72,"tags":108,"homepage":112,"download_link":113,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"wpbuoy-endpoint-manager","WPBuoy Endpoint Manager","2.1.0","Martin Cipriano","https:\u002F\u002Fprofiles.wordpress.org\u002Fmartincipriano\u002F","\u003Cp>Every plugin and theme you install registers REST API endpoints. Most are public by default — including the ones your site never uses.\u003C\u002Fp>\n\u003Cp>Unused endpoints are unnecessary exposure. They reveal information about your stack, invite probing, and become liabilities when a vulnerability is discovered in a plugin you forgot to audit.\u003C\u002Fp>\n\u003Cp>WPBuoy Endpoint Manager gives you a clear view of every endpoint on your site and a one-click toggle to disable the ones you don’t need.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>See your full API surface\u003C\u002Fstrong>\u003Cbr \u002F>\nEvery REST API endpoint from WordPress core, plugins, and themes in one organized view — grouped by namespace, with a count of how many are currently disabled.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Block endpoints instantly\u003C\u002Fstrong>\u003Cbr \u002F>\nToggle any endpoint off and it returns a 403. No code, no rules, no guesswork. One click. Requires an active Pro license.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Preview before you block\u003C\u002Fstrong>\u003Cbr \u002F>\nClick the preview icon on any static endpoint to fetch its live REST API response in an inline modal — without leaving the admin. Know exactly what you’re disabling before you disable it.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Search and filter your endpoints\u003C\u002Fstrong>\u003Cbr \u002F>\nFind any endpoint instantly with keyboard search (Ctrl\u002FCmd+F) and result highlighting. Filter by status, route type, method, or namespace to focus on what matters.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security logging\u003C\u002Fstrong>\u003Cbr \u002F>\nEvery blocked request is logged with IP address, endpoint, user agent, and timestamp — so you always know what’s being probed. Filter logs by IP, endpoint, or date range. Logs auto-clean after 30 days.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Clean and accessible\u003C\u002Fstrong>\u003Cbr \u002F>\nBuilt to WordPress admin standards. Fully keyboard-navigable with screen reader support.\u003C\u002Fp>\n\u003Ch4>Who it’s for\u003C\u002Fh4>\n\u003Cp>Agencies hardening client sites. Developers locking down staging environments. Site owners running WooCommerce, membership, or any setup where REST API exposure is a real risk.\u003C\u002Fp>\n\u003Ch4>Go further with Pro\u003C\u002Fh4>\n\u003Cp>WPBuoy Endpoint Manager Pro adds:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Endpoint blocking with a configurable response code and message (requires license)\u003C\u002Fli>\n\u003Cli>Dynamic route support with regex pattern matching\u003C\u002Fli>\n\u003Cli>Interactive preview modal for dynamic endpoints (auto-resolves default parameter values)\u003C\u002Fli>\n\u003Cli>Global rate limiting — cap the total number of REST API requests per time window\u003C\u002Fli>\n\u003Cli>Per-endpoint rate limiting — set independent limits on individual routes\u003C\u002Fli>\n\u003Cli>IP Block List — manual blocking, auto-block IPs that exceed rate limits, and an allowlist for trusted IPs\u003C\u002Fli>\n\u003Cli>CSV export of security logs\u003C\u002Fli>\n\u003Cli>Automatic plugin updates\u003C\u002Fli>\n\u003Cli>Priority support\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpbuoy.com\u002Fplugins\u002Fendpoint-manager\u002F\" rel=\"nofollow ugc\">Learn more about Endpoint Manager Pro\u003C\u002Fa>\u003C\u002Fp>\n","View, search, filter, and disable WordPress REST API endpoints. Reduce your attack surface and log blocked requests — no code required.",340,1,"2026-06-17T17:13:00.000Z","5.0",[109,19,110,111,21],"api-security","endpoint-manager","rest-api-security","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwpbuoy-endpoint-manager","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpbuoy-endpoint-manager.2.1.0.zip",{"slug":115,"name":116,"version":117,"author":118,"author_profile":119,"description":120,"short_description":121,"active_installs":122,"downloaded":123,"rating":25,"num_ratings":49,"last_updated":124,"tested_up_to":125,"requires_at_least":126,"requires_php":53,"tags":127,"homepage":129,"download_link":130,"security_score":12,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"smntcs-disable-rest-api-user-endpoints","SMNTCS Disable REST API User Endpoints","2.4","Niels Lange","https:\u002F\u002Fprofiles.wordpress.org\u002Fnielslange\u002F","\u003Cp>With WordPress 4.7 the REST API is part of the core. At the moment everyone has read access to the REST API. As a result of that a potential intruder can retrieve a list of all user slugs via \u003Ccode>\u002Fwp-json\u002Fwp\u002Fv2\u002Fusers\u003C\u002Fcode>. This plugin disables the REST API user endpoints to obscure the user slugs.\u003C\u002Fp>\n\u003Ch3>Contribute\u003C\u002Fh3>\n\u003Cp>Contributions are more than welcome. Simply head over to \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fnielslange\u002Fsmntcs-disable-rest-api-user-endpoints\u002F\" rel=\"nofollow ugc\">Github\u003C\u002Fa> and open an issue or a pull request.\u003C\u002Fp>\n","Disable the REST API user endpoints due to obscure user slugs.",7000,30284,"2024-12-31T06:23:00.000Z","6.7.5","5.5",[128,21,22],"endpoints","https:\u002F\u002Fgithub.com\u002Fnielslange\u002Fsmntcs-disable-rest-api-user-endpoints","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsmntcs-disable-rest-api-user-endpoints.2.4.zip",{"error":132,"url":133,"statusCode":134,"statusMessage":135,"message":135},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fmaxtdesign-rest-api-control\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":105,"versions":137},[138],{"version":6,"download_url":24,"svn_tag_url":139,"released_at":26,"has_diff":140,"diff_files_changed":141,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":142,"is_current":132},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmaxtdesign-rest-api-control\u002Ftags\u002F1.0.5\u002F",false,[],[]]