[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fo-Fxit7_0rswiWSG-UQetpTIp9JHh2p-ZrIL3Gg0zzo":3,"$faZwZYYpO8d1IzHB9Vy2IkeIbiMco9t9C2yfGMS-pnrU":133,"$fYHoZ5XGTv_Uy6tj5lxCi3ESDewXeCL_hHyORQ2QCuiA":138},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":38,"analysis":27,"fingerprints":27},"wpbuoy-endpoint-manager","WPBuoy Endpoint Manager","2.1.0","Martin Cipriano","https:\u002F\u002Fprofiles.wordpress.org\u002Fmartincipriano\u002F","\u003Cp>Every plugin and theme you install registers REST API endpoints. Most are public by default — including the ones your site never uses.\u003C\u002Fp>\n\u003Cp>Unused endpoints are unnecessary exposure. They reveal information about your stack, invite probing, and become liabilities when a vulnerability is discovered in a plugin you forgot to audit.\u003C\u002Fp>\n\u003Cp>WPBuoy Endpoint Manager gives you a clear view of every endpoint on your site and a one-click toggle to disable the ones you don’t need.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>See your full API surface\u003C\u002Fstrong>\u003Cbr \u002F>\nEvery REST API endpoint from WordPress core, plugins, and themes in one organized view — grouped by namespace, with a count of how many are currently disabled.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Block endpoints instantly\u003C\u002Fstrong>\u003Cbr \u002F>\nToggle any endpoint off and it returns a 403. No code, no rules, no guesswork. One click. Requires an active Pro license.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Preview before you block\u003C\u002Fstrong>\u003Cbr \u002F>\nClick the preview icon on any static endpoint to fetch its live REST API response in an inline modal — without leaving the admin. Know exactly what you’re disabling before you disable it.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Search and filter your endpoints\u003C\u002Fstrong>\u003Cbr \u002F>\nFind any endpoint instantly with keyboard search (Ctrl\u002FCmd+F) and result highlighting. Filter by status, route type, method, or namespace to focus on what matters.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security logging\u003C\u002Fstrong>\u003Cbr \u002F>\nEvery blocked request is logged with IP address, endpoint, user agent, and timestamp — so you always know what’s being probed. Filter logs by IP, endpoint, or date range. Logs auto-clean after 30 days.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Clean and accessible\u003C\u002Fstrong>\u003Cbr \u002F>\nBuilt to WordPress admin standards. Fully keyboard-navigable with screen reader support.\u003C\u002Fp>\n\u003Ch4>Who it’s for\u003C\u002Fh4>\n\u003Cp>Agencies hardening client sites. Developers locking down staging environments. Site owners running WooCommerce, membership, or any setup where REST API exposure is a real risk.\u003C\u002Fp>\n\u003Ch4>Go further with Pro\u003C\u002Fh4>\n\u003Cp>WPBuoy Endpoint Manager Pro adds:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Endpoint blocking with a configurable response code and message (requires license)\u003C\u002Fli>\n\u003Cli>Dynamic route support with regex pattern matching\u003C\u002Fli>\n\u003Cli>Interactive preview modal for dynamic endpoints (auto-resolves default parameter values)\u003C\u002Fli>\n\u003Cli>Global rate limiting — cap the total number of REST API requests per time window\u003C\u002Fli>\n\u003Cli>Per-endpoint rate limiting — set independent limits on individual routes\u003C\u002Fli>\n\u003Cli>IP Block List — manual blocking, auto-block IPs that exceed rate limits, and an allowlist for trusted IPs\u003C\u002Fli>\n\u003Cli>CSV export of security logs\u003C\u002Fli>\n\u003Cli>Automatic plugin updates\u003C\u002Fli>\n\u003Cli>Priority support\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpbuoy.com\u002Fplugins\u002Fendpoint-manager\u002F\" rel=\"nofollow ugc\">Learn more about Endpoint Manager Pro\u003C\u002Fa>\u003C\u002Fp>\n","View, search, filter, and disable WordPress REST API endpoints. Reduce your attack surface and log blocked requests — no code required.",0,340,100,1,"2026-06-17T17:13:00.000Z","7.0.2","5.0","7.4",[20,21,22,23,24],"api-security","disable-rest-api","endpoint-manager","rest-api-security","rest-api","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwpbuoy-endpoint-manager","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpbuoy-endpoint-manager.2.1.0.zip",null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":32,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":34,"avg_patch_time_days":35,"trust_score":36,"computed_at":37},"martincipriano",2,96,30,91,"2026-08-26T11:16:59.027Z",[39,57,80,96,115],{"slug":40,"name":41,"version":42,"author":43,"author_profile":44,"description":45,"short_description":46,"active_installs":11,"downloaded":47,"rating":11,"num_ratings":11,"last_updated":48,"tested_up_to":16,"requires_at_least":17,"requires_php":49,"tags":50,"homepage":55,"download_link":56,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28},"authyo-passwordless-login","Authyo Passwordless Login","1.0.8","Konceptwise Digital Media Pvt Ltd","https:\u002F\u002Fprofiles.wordpress.org\u002Fkonceptwise\u002F","\u003Cp>Authyo Passwordless Login is a WordPress login security plugin that protects your site with brute-force protection, IP blacklisting, security activity logs, XML-RPC blocking, REST API protection, and a custom login URL. All security features work immediately after activation — no API keys or account registration needed.\u003C\u002Fp>\n\u003Cp>Optionally, add Authyo API credentials to enable passwordless OTP login where users log in with a one-time password sent to their email instead of a traditional password.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security features that work without API keys:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Brute-force protection\u003C\u002Fstrong> — Limit login attempts per IP and username with progressive lockout durations. Repeat offenders are automatically blacklisted.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Manager\u003C\u002Fstrong> — Whitelist trusted IPs and blacklist attackers. Includes search, filter, pagination, and per-page selector for large lists.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security activity logs\u003C\u002Fstrong> — Track every login, logout, failed attempt, lockout, and blocked access. Includes request URL tracking, date filters, search, and CSV export.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable XML-RPC\u003C\u002Fstrong> — Block xmlrpc.php requests at the server level using .htaccess rules. Removes X-Pingback headers and XML-RPC discovery links. Falls back to PHP blocking on Nginx.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API Protection\u003C\u002Fstrong> — Restrict access to WordPress REST API endpoints for unauthenticated users. Prevents data enumeration and unauthorized access while keeping essential endpoints functional.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom login URL\u003C\u002Fstrong> — Hide wp-login.php behind a custom URL slug to prevent automated attacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocked IP logging\u003C\u002Fstrong> — Every access attempt from blacklisted or locked-out IPs is logged with IP address, user agent, and request URL.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Passwordless login features (requires free Authyo API keys):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Email OTP login\u003C\u002Fstrong> — Users receive a one-time password via email and log in without a traditional password.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Authenticator fallback\u003C\u002Fstrong> — Server-side verified 2FA as a backup method after multiple OTP attempts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure login tokens\u003C\u002Fstrong> — Cryptographically generated, single-use, browser-bound tokens that expire after 5 minutes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AJAX-powered login\u003C\u002Fstrong> — Smooth login experience with no page reloads.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Video Tutorial\u003C\u002Fh3>\n\u003Cp>Learn how Authyo Passwordless Login works:\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FcStBvoHTzro?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch3>How It Works\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Security (works immediately after activation):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Activate the plugin — brute-force protection and security logs start automatically\u003C\u002Fli>\n\u003Cli>Go to Settings > Authyo Passwordless Login > Security tab\u003C\u002Fli>\n\u003Cli>Enable XML-RPC Protection, REST API Protection, and Custom Login URL as needed\u003C\u002Fli>\n\u003Cli>Visit Authyo Logs to monitor activity and manage IPs\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Passwordless login (requires API keys):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>User enters their email on the WordPress login page\u003C\u002Fli>\n\u003Cli>A one-time password (OTP) is sent to their email\u003C\u002Fli>\n\u003Cli>User enters the OTP code\u003C\u002Fli>\n\u003Cli>WordPress logs the user in automatically — no password required\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to Authyo’s external API only for passwordless login and Google Authenticator features. All security features (brute-force protection, IP manager, security logs, XML-RPC protection, REST API protection, custom login URL) work locally without any external service.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>OTP Authentication:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>User email address is sent to Authyo API when requesting an OTP\u003C\u002Fli>\n\u003Cli>OTP code and Mask ID are sent to Authyo API for verification\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Google Authenticator Verification:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Verification token is sent to Authyo API for server-side validation\u003C\u002Fli>\n\u003Cli>The Authyo 2FA SDK script is loaded from \u003Ca href=\"https:\u002F\u002Fapp.authyo.io\u002Fjs\u002Fv1\u002Fauth-2fasdk.js\" rel=\"nofollow ugc\">https:\u002F\u002Fapp.authyo.io\u002Fjs\u002Fv1\u002Fauth-2fasdk.js\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Usage Tracking (Opt-In Only):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If the user explicitly opts in, plugin version, WordPress version, and site URL are sent when settings are saved. Deactivation feedback is sent when the plugin is deactivated. No tracking data is sent without user consent.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Authentication Flow:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>After OTP verification, the plugin generates a secure single-use token using WordPress core functions\u003C\u002Fli>\n\u003Cli>Token is browser-bound using a hashed User-Agent signature to prevent session hijacking\u003C\u002Fli>\n\u003Cli>Token is stored temporarily in WordPress transients (5-minute expiry) and deleted immediately after use\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Data Storage:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>OTP session data stored temporarily in WordPress transients (10-minute expiry)\u003C\u002Fli>\n\u003Cli>Login tokens stored temporarily in WordPress transients (5-minute expiry, single-use)\u003C\u002Fli>\n\u003Cli>Security logs stored in a custom database table with configurable retention\u003C\u002Fli>\n\u003Cli>IP whitelist and blacklist stored in a custom database table\u003C\u002Fli>\n\u003Cli>No user data is permanently stored beyond security logs\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Service URLs:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>API: \u003Ca href=\"https:\u002F\u002Fapp.authyo.io\u002Fapi\u002Fv1\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fapp.authyo.io\u002Fapi\u002Fv1\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>2FA SDK: \u003Ca href=\"https:\u002F\u002Fapp.authyo.io\u002Fjs\u002Fv1\u002Fauth-2fasdk.js\" rel=\"nofollow ugc\">https:\u002F\u002Fapp.authyo.io\u002Fjs\u002Fv1\u002Fauth-2fasdk.js\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fauthyo.io\u002Fterms-service\" rel=\"nofollow ugc\">https:\u002F\u002Fauthyo.io\u002Fterms-service\u003C\u002Fa>\u003Cbr \u002F>\n\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fauthyo.io\u002Fprivacy-policy\" rel=\"nofollow ugc\">https:\u002F\u002Fauthyo.io\u002Fprivacy-policy\u003C\u002Fa>\u003C\u002Fp>\n","WordPress login security with brute-force protection, IP manager, security logs, XML-RPC protection, REST API protection, and passwordless OTP login.",791,"2026-07-08T09:07:00.000Z","7.2",[51,52,53,54,23],"brute-force-protection","disable-xmlrpc","login-security","passwordless-login","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fauthyo-passwordless-login.1.0.8.zip",{"slug":58,"name":59,"version":60,"author":61,"author_profile":62,"description":63,"short_description":64,"active_installs":65,"downloaded":66,"rating":67,"num_ratings":33,"last_updated":68,"tested_up_to":69,"requires_at_least":70,"requires_php":71,"tags":72,"homepage":77,"download_link":78,"security_score":79,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28},"wpcontrol","WPControl – The Easiest Optimization Plugin for WordPress","1.0.1","Syed Balkhi","https:\u002F\u002Fprofiles.wordpress.org\u002Fsmub\u002F","\u003Cp>WPControl is the ultimate way to clean up your WordPress site.\u003C\u002Fp>\n\u003Cp>With over 20 built-in optimizations, WPControl allows you to easily enable and disable WordPress Core features, letting you remove those features that you don’t use from the dashboard you and your users see.\u003C\u002Fp>\n\u003Cp>Simply put, WPControl is the ultimate plugin that you need to control your website. With our single plugin, you can remove the need to have plugins for things like:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disabling emails\u003C\u002Fli>\n\u003Cli>Disabling comments\u003C\u002Fli>\n\u003Cli>Disabling the WordPress REST API\u003C\u002Fli>\n\u003Cli>and so much more\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All in a single, easy to use plugin that helps boost both the performance and security of your WordPress install.\u003C\u002Fp>\n\u003Cp>WPControl is designed for simplicity first, made by the same \u003Ca href=\"https:\u002F\u002Fwpbeginner.com\u002F\" title=\"WPBeginner\" rel=\"friend nofollow ugc\">WPBeginner team\u003C\u002Fa> that makes your favorite WordPress tutorials.\u003C\u002Fp>\n\u003Cp>Our plugin is used by the plugin authors behind many of your favorite WordPress plugins including \u003Ca href=\"https:\u002F\u002Fwww.monsterinsights.com\u002F\" title=\"MonsterInsights\" rel=\"friend nofollow ugc\">MonsterInsights\u003C\u002Fa> , \u003Ca href=\"https:\u002F\u002Fwpforms.com\u002F\" title=\"WPForms\" rel=\"friend nofollow ugc\">WPForms\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Faioseo.com\u002F\" title=\"AIOSEO\" rel=\"friend nofollow ugc\">AIOSEO\u003C\u002Fa>  and more.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>Simple, yet powerful. I love that I can easily disable all of the features of WordPress I’m not using in a single plugin. It makes new site setup a breeze!\u003Cbr \u002F>\n  \u003Cbr \u002F>\n  Chris Christoff\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>At WPControl, we found that there are many unused features of WordPress that make it a hassle sometimes or we just don’t need. There are tons of plugins already out there that will disable a specific feature. But taking the time and energy to optimize all of them was too much. We made just one plugin that has the features of many so you can have a one stop shop for disabling unused features of WordPress.\u003C\u002Fp>\n\u003Cp>Unlike other methods of disabling features, WPControl allows you to disable many features with just a few clicks (no need to hire a developer).\u003C\u002Fp>\n\u003Ch4>Settings Include\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Comments\u003C\u002Fstrong> – You can disable comments site wide or on specific post types such as posts, pages, and media.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Gutenberg\u003C\u002Fstrong> – Disables the Gutenberg block editor and reverts it the Classic Editor\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable “Try Gutenberg” Nag\u003C\u002Fstrong> – Removes the annoying admin notice that keeps nagging you to try Gutenberg\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Shortlinks\u003C\u002Fstrong> – The tag is auto generated by WordPress and is used to create shortlinks. If you are already using pretty permalinks, such as the PrettyLinks plugin. Then there is no need for this unnecessary tag.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable RSD Link\u003C\u002Fstrong> – RSD Links are used by blog clients and some 3rd parties that utilize XML-RPC requests. If you edit your site through your browser, then you do not need it. Most of the time, it is just unnecessary code.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Remove XFN Profile Link\u003C\u002Fstrong> – The XFN Profile Link is used to add semantic data to links to be used by browsers to assign relationships between profiles. Basically it tells browsers that the site contains links that use XFN Specification\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable wlwmanifest Link\u003C\u002Fstrong> – The wlwmanifest link is used by Windows Live Writer. If you don’t use Windows Live Writer then disable the link as it is unnecessary code.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Links to Previous and Next Post\u003C\u002Fstrong> – If your site is not a blog and is used as a CMS, then this feature will remove the previous and next post links in your WordPress theme.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable XML-RPC Pingback\u003C\u002Fstrong> – Removes XML-RPC method to prevent abuse of site’s pingback while you can use the rest of the XML-RPC Pingback method.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Gravatar\u003C\u002Fstrong> – Blocks users WordPress from getting user Gravatar from their email to add privacy for the users or prevent inappropriate avatars.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Rest API\u003C\u002Fstrong> – Disables the REST-API to prevent abuse of Rest\u002FJSON API.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Hide Login Errors\u003C\u002Fstrong> – An attacker can find the authors login using a similar request as mysite.com\u002F?author=1.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Remove HTML comments\u003C\u002Fstrong> – Removes HTML comments in source code to add a layer of defense from attackers trying to find the version of plugins.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Remove Meta Generator\u003C\u002Fstrong> – This meta tag allows attackers to see the version of WordPress, it serves no useful purpose.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Right Click\u003C\u002Fstrong> – You can disable the ability to right click on your site, or just specific things like posts, pages, media, front page, and even have the ability to show an alert to the user that right click is disabled.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Admin Notices\u003C\u002Fstrong> – You can disable all admin notices that appear in the admin settings page.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable New User Emails\u003C\u002Fstrong> – Stops WordPress from sending new user notification emails to admin.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Search\u003C\u002Fstrong> – Disable the front-end search bar in WordPress.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Lazy Loading\u003C\u002Fstrong> – Removes the lazy loading functionality that was added in WordPress 5.3.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Hide Admin Toolbar\u003C\u002Fstrong> – Hides the admin toolbar when the admin is on the front-end\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Dashboard Widgets\u003C\u002Fstrong> – Gives you the option to disable whichever default dashboard widgets you want.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>After reading this feature list, you can probably imagine why WPControl is the best disable plugin for WordPress.\u003C\u002Fp>\n\u003Cp>Give WPControl a try today!\u003C\u002Fp>\n\u003Ch4>Credits\u003C\u002Fh4>\n\u003Cp>This plugin is created by Zain Balkhi of the \u003Ca href=\"https:\u002F\u002Fwpbeginner.com\u002F\" title=\"WPBeginner\" rel=\"friend nofollow ugc\">WPBeginner team\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>What’s Next\u003C\u002Fh4>\n\u003Cp>If you like this plugin, then consider checking out our other projects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.monsterinsights.com\u002F\" title=\"MonsterInsights\" rel=\"friend nofollow ugc\">MonsterInsights\u003C\u002Fa> – Best Google Analytics plugin for WordPress\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Foptinmonster.com\u002F\" title=\"OptinMonster\" rel=\"friend nofollow ugc\">OptinMonster\u003C\u002Fa> – Get More Email Subscribers\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpforms.com\u002F\" title=\"WPForms\" rel=\"friend nofollow ugc\">WPForms\u003C\u002Fa> – Best WordPress Contact Form Plugin\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Faioseo.com\u002F\" title=\"AIOSEO\" rel=\"friend nofollow ugc\">AIOSEO\u003C\u002Fa> – The original WordPress SEO plugin to help you rank higher in search results (trusted by over 2 million sites)\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.seedprod.com\u002F\" title=\"SeedProd\" rel=\"friend nofollow ugc\">SeedProd\u003C\u002Fa> – Most popular coming soon & maintenance mode plugin for WordPress\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpmailsmtp.com\u002F\" title=\"WP Mail SMTP\" rel=\"friend nofollow ugc\">WP Mail SMTP\u003C\u002Fa> – Improve email deliverability for your contact form with the most popular SMTP plugin for WordPress\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Frafflepress.com\u002F\" title=\"RafflePress\" rel=\"friend nofollow ugc\">RafflePress\u003C\u002Fa> – Best WordPress giveaway and contest plugin to grow traffic and social followers\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fsmashballoon.com\u002F\" title=\"Smash Balloon\" rel=\"friend nofollow ugc\">Smash Balloon\u003C\u002Fa> – #1 social feeds plugin for WordPress – display social media content in WordPress without code\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpushengage.com\u002F\" title=\"PushEngage\" rel=\"friend nofollow ugc\">PushEngage\u003C\u002Fa> – Connect with visitors after they leave your website with the leading web push notification plugin\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Ftrustpulse.com\u002F\" title=\"TrustPulse\" rel=\"friend nofollow ugc\">TrustPulse\u003C\u002Fa> – Add real-time social proof notifications to boost your store conversions by up to 15%\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin would not be possible without the help and support of \u003Ca href=\"http:\u002F\u002Fwww.wpbeginner.com\u002F\" title=\"WPBeginner\" rel=\"friend nofollow ugc\">WPBeginner\u003C\u002Fa>, the largest WordPress resource site. You can learn from our \u003Ca href=\"http:\u002F\u002Fwww.wpbeginner.com\u002Fcategory\u002Fwp-tutorials\u002F\" title=\"WordPress Tutorials\" rel=\"friend nofollow ugc\">free WordPress Tutorials\u003C\u002Fa> like \u003Ca href=\"http:\u002F\u002Fwww.wpbeginner.com\u002Fhow-to-install-wordpress\u002F\" title=\"How to Install WordPress - Step by Step\" rel=\"friend nofollow ugc\">how to install WordPress\u003C\u002Fa>, \u003Ca href=\"http:\u002F\u002Fwww.wpbeginner.com\u002Fwordpress-hosting\u002F\" title=\"How to choose the best WordPress hosting\" rel=\"friend nofollow ugc\">choose the best WordPress hosting\u003C\u002Fa>, \u003Ca href=\"http:\u002F\u002Fwww.wpbeginner.com\u002Fglossary\u002F\" title=\"WordPress Glossary Terms for Beginners\" rel=\"friend nofollow ugc\">WordPress glossary\u003C\u002Fa>, and more.\u003C\u002Fp>\n\u003Cp>You can also learn about other \u003Ca href=\"http:\u002F\u002Fwww.wpbeginner.com\u002Fcategory\u002Fplugins\u002F\" title=\"Best WordPress Plugins\" rel=\"friend nofollow ugc\">best WordPress plugins\u003C\u002Fa>.\u003C\u002Fp>\n","The easiest way to improve your website's security, performance, and user experience.",200,4625,90,"2022-04-18T21:12:00.000Z","5.9.13","3.8.0","5.6",[73,74,21,75,76],"disable-comments","disable-gutenberg","performance","security","https:\u002F\u002Fwww.wpcontrol.com\u002F?utm_source=liteplugin&utm_medium=pluginheader&utm_campaign=pluginurl&utm_content=7%2E0%2E0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpcontrol.1.0.1.zip",85,{"slug":81,"name":82,"version":83,"author":84,"author_profile":85,"description":86,"short_description":87,"active_installs":13,"downloaded":88,"rating":11,"num_ratings":11,"last_updated":89,"tested_up_to":16,"requires_at_least":90,"requires_php":18,"tags":91,"homepage":94,"download_link":95,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28},"turn-off-rest-api","Turn Off REST API","1.1.1","ksym04","https:\u002F\u002Fprofiles.wordpress.org\u002Fksym04\u002F","\u003Cp>\u003Cstrong>Turn Off REST API\u003C\u002Fstrong> is a lightweight WordPress security plugin that disables the WordPress REST API for visitors who are not logged in. Anonymous requests to your \u003Ccode>\u002Fwp-json\u003C\u002Fcode> endpoints receive an authentication error instead of your site data, while logged in users, your theme, and your plugins keep working normally.\u003C\u002Fp>\n\u003Cp>By default WordPress exposes a large amount of information through the REST API, including your list of user accounts and usernames, published content, and details about your site. For most sites that open, unauthenticated access is unnecessary and only widens the attack surface for user enumeration and content scraping. Turn Off REST API closes the WordPress REST API to the public in one click, then gives you a clear settings screen to reopen only the specific REST API routes you actually need.\u003C\u002Fp>\n\u003Ch4>Why turn off the WordPress REST API?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Stop anonymous user enumeration through \u003Ccode>\u002Fwp-json\u002Fwp\u002Fv2\u002Fusers\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>Reduce your attack surface against REST API based exploits and bots.\u003C\u002Fli>\n\u003Cli>Keep your content and site data from being scraped through the public API.\u003C\u002Fli>\n\u003Cli>Stay in control with a per route allow list instead of an all or nothing switch.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What it does\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Returns an authentication error for unauthenticated REST API requests.\u003C\u002Fli>\n\u003Cli>Optionally removes the REST API discovery links and headers from your page source.\u003C\u002Fli>\n\u003Cli>Lets you build an allow list of routes that should stay public (for example a contact form or a specific integration).\u003C\u002Fli>\n\u003Cli>Adds a Site Health check so the restriction is clearly explained and never mistaken for a fault.\u003C\u002Fli>\n\u003Cli>Keeps the admin area, the block editor, and logged in functionality fully working.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Built for control, not breakage\u003C\u002Fh4>\n\u003Cp>Some security plugins disable the REST API completely and break the block editor or third party integrations in the process. Turn Off REST API only blocks unauthenticated access, and the per route allow list means you can whitelist exactly the endpoints a service needs without opening the whole API back up.\u003C\u002Fp>\n\u003Ch4>Developer friendly\u003C\u002Fh4>\n\u003Cp>The access decision runs through the \u003Ccode>tora_grant_rest_api\u003C\u002Fcode> filter, so developers can extend or override the logic for custom roles, application passwords, or trusted requests.\u003C\u002Fp>\n","Disable the WordPress REST API for logged out visitors and lock down your \u002Fwp-json endpoints, with a per route allow list so you stay in control.",3050,"2026-06-27T19:25:00.000Z","4.7",[21,92,24,76,93],"json","wp-json","https:\u002F\u002Fwww.dopethemes.com\u002Fdownloads\u002Fturn-off-rest-api\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fturn-off-rest-api.1.1.1.zip",{"slug":97,"name":98,"version":99,"author":100,"author_profile":101,"description":102,"short_description":103,"active_installs":104,"downloaded":105,"rating":11,"num_ratings":11,"last_updated":106,"tested_up_to":107,"requires_at_least":108,"requires_php":55,"tags":109,"homepage":113,"download_link":114,"security_score":79,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28},"server-response","Server Response","1.1","seoriver","https:\u002F\u002Fprofiles.wordpress.org\u002Fseoriver\u002F","\u003Cp>Server Response поможет вам скорректировать заголовки ответа сервера и отключить REST API.\u003C\u002Fp>\n\u003Cp>Функции плагина:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>Отключение REST API.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Удаление ссылки на REST API из ответа сервера.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Актуализация даты заголовков Expires и Last-Modified в ответе сервера. Создание данных заголовков, если они отсутствуют.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Удаление rel=shortlink из ответа сервера.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n","Поможет вам скорректировать заголовки ответа сервера и отключить REST API.",10,1800,"2017-08-04T01:27:00.000Z","4.8.28","4.6",[21,110,111,112,97],"disable-wp-json","expires","last-modified","http:\u002F\u002Fseo-river.ru\u002Fserver-response\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fserver-response.zip",{"slug":116,"name":117,"version":118,"author":119,"author_profile":120,"description":121,"short_description":122,"active_installs":11,"downloaded":123,"rating":11,"num_ratings":11,"last_updated":124,"tested_up_to":125,"requires_at_least":126,"requires_php":127,"tags":128,"homepage":130,"download_link":131,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":27,"fetched_at":132},"caledros-helper","Caledros Helper","1.0.0","David Arnado","https:\u002F\u002Fprofiles.wordpress.org\u002Fdarnado\u002F","\u003Cp>This plugin creates a custom Admin Menu with two checkboxes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>The first checkbox allows the user to remove the core block patterns from the Gutenberg editor. This feature can be activated or deactivated.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>The second checkbox allows the user to deactivate the WordPress REST API for non-authenticated users. This feature can be activated or deactivated.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>After plugin activation, both options will be disabled by default.\u003C\u002Fp>\n","Adds an Admin Menu that allows removing the default block patterns. It also allows deactivating the WordPress REST API for non-authenticated users.",310,"2025-12-14T16:59:00.000Z","6.9.4","6.8","8.3",[129,21],"disable-patterns","https:\u002F\u002Fcaledrosforge.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcaledros-helper.1.0.0.zip","2026-04-16T10:56:18.058Z",{"error":134,"url":135,"statusCode":136,"statusMessage":137,"message":137},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fwpbuoy-endpoint-manager\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":139,"versions":140},5,[141,147,154,161,168],{"version":6,"download_url":26,"svn_tag_url":142,"released_at":27,"has_diff":143,"diff_files_changed":144,"diff_lines":27,"trac_diff_url":145,"vulnerabilities":146,"is_current":134},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwpbuoy-endpoint-manager\u002Ftags\u002F2.1.0\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwpbuoy-endpoint-manager%2Ftags%2F2.0.1&new_path=%2Fwpbuoy-endpoint-manager%2Ftags%2F2.1.0",[],{"version":148,"download_url":149,"svn_tag_url":150,"released_at":27,"has_diff":143,"diff_files_changed":151,"diff_lines":27,"trac_diff_url":152,"vulnerabilities":153,"is_current":143},"2.0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpbuoy-endpoint-manager.2.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwpbuoy-endpoint-manager\u002Ftags\u002F2.0.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwpbuoy-endpoint-manager%2Ftags%2F2.0.0&new_path=%2Fwpbuoy-endpoint-manager%2Ftags%2F2.0.1",[],{"version":155,"download_url":156,"svn_tag_url":157,"released_at":27,"has_diff":143,"diff_files_changed":158,"diff_lines":27,"trac_diff_url":159,"vulnerabilities":160,"is_current":143},"2.0.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpbuoy-endpoint-manager.2.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwpbuoy-endpoint-manager\u002Ftags\u002F2.0.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwpbuoy-endpoint-manager%2Ftags%2F1.1.4&new_path=%2Fwpbuoy-endpoint-manager%2Ftags%2F2.0.0",[],{"version":162,"download_url":163,"svn_tag_url":164,"released_at":27,"has_diff":143,"diff_files_changed":165,"diff_lines":27,"trac_diff_url":166,"vulnerabilities":167,"is_current":143},"1.1.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpbuoy-endpoint-manager.1.1.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwpbuoy-endpoint-manager\u002Ftags\u002F1.1.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwpbuoy-endpoint-manager%2Ftags%2F1.1.2&new_path=%2Fwpbuoy-endpoint-manager%2Ftags%2F1.1.4",[],{"version":169,"download_url":170,"svn_tag_url":171,"released_at":27,"has_diff":143,"diff_files_changed":172,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":173,"is_current":143},"1.1.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpbuoy-endpoint-manager.1.1.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwpbuoy-endpoint-manager\u002Ftags\u002F1.1.2\u002F",[],[]]