Title: Turn Off REST API
Author: ksym04
Published: <strong>Maret 23, 2017</strong>
Last modified: Septèmber 24, 2026

---

Nggoléki Plugin

![](https://ps.w.org/turn-off-rest-api/assets/icon-256x256.png?rev=3585859)

# Turn Off REST API

 Dening [ksym04](https://profiles.wordpress.org/ksym04/)

[Ngundhuh](https://downloads.wordpress.org/plugin/turn-off-rest-api.1.1.4.zip)

 * [Detil](https://jv.wordpress.org/plugins/turn-off-rest-api/#description)
 * [Mācā ulang](https://jv.wordpress.org/plugins/turn-off-rest-api/#reviews)
 *  [Pemasangan](https://jv.wordpress.org/plugins/turn-off-rest-api/#installation)
 * [Pangembangan](https://jv.wordpress.org/plugins/turn-off-rest-api/#developers)

 [Sokong](https://wordpress.org/support/plugin/turn-off-rest-api/)

## Katrangan

**Turn Off REST API** is a lightweight WordPress security plugin that disables the
WordPress REST API for visitors who are not logged in. Anonymous requests to your`/
wp-json` endpoints receive an authentication error instead of your site data, while
logged in users, the block editor, and your admin area keep working normally.

Because every route is blocked for logged out visitors by default, features that
call the REST API on behalf of visitors stop working for them until you allow their
routes. This includes the WooCommerce Cart and Checkout blocks and Contact Form 
7 form submissions. The FAQ below shows exactly which routes to allow.

By default WordPress exposes a large amount of information through the REST API,
including your list of user accounts and usernames, published content, and details
about your site. For most sites that open, unauthenticated access is unnecessary
and only widens the attack surface for user enumeration and content scraping. Turn
Off REST API closes the WordPress REST API to the public in one click, then gives
you a clear settings screen to reopen only the specific REST API routes you actually
need.

#### Why turn off the WordPress REST API?

 * Stop anonymous user enumeration through `/wp-json/wp/v2/users`.
 * Reduce your attack surface against REST API based exploits and bots.
 * Keep your content and site data from being scraped through the public API.
 * Stay in control with a per route allow list instead of an all or nothing switch.

#### What it does

 * Returns an authentication error for unauthenticated REST API requests.
 * Optionally removes the REST API discovery links and headers from your page source.
 * Lets you build an allow list of routes that should stay public (for example a
   contact form or a specific integration).
 * Adds a Site Health check so the restriction is clearly explained and never mistaken
   for a fault.
 * Keeps the admin area, the block editor, and logged in functionality fully working.

#### Built for control, not breakage

Some security plugins disable the REST API completely and break the block editor
or third party integrations in the process. Turn Off REST API only blocks unauthenticated
access, and the per route allow list means you can whitelist exactly the endpoints
a service needs without opening the whole API back up.

#### Developer friendly

The access decision runs through the `tora_grant_rest_api` filter, so developers
can extend or override the logic for custom roles, application passwords, or trusted
requests.

## Gambar conto

[⌊A logged out visitor opening /wp-json gets an authentication error (status 401)
instead of your site data.⌉⌊A logged out visitor opening /wp-json gets an authentication
error (status 401) instead of your site data.⌉[

A logged out visitor opening `/wp-json` gets an authentication error (status 401)
instead of your site data.

## Pemasangan

 1. In your WordPress admin, go to Plugins, then Add New.
 2. Search for “Turn Off REST API”.
 3. Click Install Now, then Activate.
 4. Go to Settings, then Turn Off REST API to review the route allow list. Unauthenticated
    access is disabled by default. If your site uses the WooCommerce Cart or Checkout
    blocks or Contact Form 7, allow their routes as described in the FAQ.

Manual installation:

 1. Download the plugin zip from WordPress.org.
 2. Upload the `turn-off-rest-api` folder to `/wp-content/plugins/`.
 3. Activate the plugin through the Plugins menu in WordPress.

## FAQ

### How do I confirm the REST API is blocked?

Log out of your site (or open a private browser window) and visit `https://your-
site.com/wp-json`. You should see an authentication error instead of a list of routes
and data. Logged in users will still see the normal response.

### Will this break the block editor (Gutenberg)?

No. The block editor runs as a logged in user, so it keeps full REST API access.
Only unauthenticated requests are blocked.

### I need one endpoint to stay public. Can I allow just that route?

Yes. Open Settings, then Turn Off REST API, check the route or namespace you want
to keep open, and save. Everything else stays blocked.

### My WooCommerce cart or checkout, or my Contact Form 7 form, stopped working for visitors. How do I fix it?

These features send REST API requests on behalf of logged out visitors, and the 
plugin blocks every route for visitors until you allow it. The WooCommerce Cart 
and Checkout blocks use the routes under `/wc/store/v1`. Contact Form 7 sends each
form submission through its own routes under `/contact-form-7/v1`.

 1. Go to Settings, then Turn Off REST API.
 2. Under Allowed REST API Routes, find the `/wc/store/v1` heading and check its box.
    This also checks every route listed under it. The separate `/wc/store` heading 
    above it is not used by the blocks.
 3. For Contact Form 7, find the `/contact-form-7/v1` heading and check only the three
    routes under it that end in `/feedback`, `/feedback/schema`, and `/refill`.
 4. Click Save Changes.

Only the routes you check are opened, and everything else stays blocked. If a later
WooCommerce or Contact Form 7 update adds a new route, come back to this screen 
and check it as well.

### Does it work on nginx as well as Apache?

Yes. The plugin works at the WordPress request level and does not depend on any 
web server configuration files.

### Can developers customize who is allowed?

Yes. Use the `tora_grant_rest_api` filter to return true or false based on your 
own logic. By default it returns whether the current user is logged in.

## Mācā ulang

There are no reviews for this plugin.

## Contributors & Developers

“Turn Off REST API” is open source software. The following people have contributed
to this plugin.

Kontributor

 *   [ ksym04 ](https://profiles.wordpress.org/ksym04/)

[Translate “Turn Off REST API” into your language.](https://translate.wordpress.org/projects/wp-plugins/turn-off-rest-api)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/turn-off-rest-api/),
check out the [SVN repository](https://plugins.svn.wordpress.org/turn-off-rest-api/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/turn-off-rest-api/)
by [RSS](https://plugins.trac.wordpress.org/log/turn-off-rest-api/?limit=100&mode=stop_on_copy&format=rss).

## Caathetan Owahan

#### 1.1.4

 * Tested with WordPress 7.1.2.
 * Fixed – security: when another security plugin or your own code had already blocked
   a REST API request from a logged out visitor, this plugin could lift that block
   and let the request through. The earlier block is now always kept.
 * Fixed – the option to hide REST API discovery links and headers now also removes
   the REST API link that WordPress sends in the headers of every page. Before, 
   only the links in the page source were removed.
 * Fixed – the settings screen no longer stops with an error when a save request
   contains malformed route data. Such a request is treated like one with no routes
   ticked.
 * Tweak – removed support code for WordPress versions older than 4.7, which the
   plugin already required.

#### 1.1.3

 * Fixed – WordPress 6.7 and newer logged a “translation loading was triggered too
   early” notice for this plugin on sites with debugging enabled. The plugin name
   was being translated while the plugin loaded, before WordPress is ready to serve
   translations.
 * Tweak – the version used to cache bust the settings screen assets now comes from
   a single source, so it can never fall out of step with the plugin version again.
 * No change to how the REST API is protected.

#### 1.1.2

 * Tested with WordPress 7.1.
 * Fixed – a PHP notice on PHP 8.2 and newer, caused by a plugin property being 
   created on the fly instead of being declared. On a future PHP 9 this would have
   stopped the plugin from loading.
 * Fixed – the settings screen stylesheet and script were still labelled with the
   previous version number, so browsers could keep serving the old cached files 
   after an update.
 * No change to how the REST API is protected.

#### 1.1.1

 * New – A “More on DopeThemes” panel on the settings screen with free plugins, 
   code snippets, themes, and tutorials. No change to how the REST API is protected.

#### 1.1.0

 * New – Site Health check that confirms the REST API is intentionally restricted,
   so it is never mistaken for an error.
 * New – Option to show or hide the REST API discovery links and headers in your
   page source.
 * Tweak – Clearer settings screen with a protection status and a dedicated options
   section.

#### 1.0.5

 * Tweak – Confirmed compatibility with WordPress 7.0.
 * Fix – PHP 8 compatibility: resolved an undefined array key warning during REST
   route detection.
 * Fix – Hardened output escaping on the settings screen.
 * Fix – Corrected the internationalization of the authentication error message.
 * Tweak – Added Requires PHP header and refreshed the plugin documentation.

#### 1.0.4

 * New – Update license to GPLv3
 * Tweak – Compatibility with WP 5+
 * Tweak – Update language file
 * Tweak – Minor improvements

#### 1.0.3

 * Tweak – Added en_US language file
 * Tweak – Added license file
 * Tweak – Minor code clean up

#### 1.0.2

 * Tweak – Added endpoints admin page
 * Tweak – Minor improvements

#### 1.0.1

 * Tweak – Minor improvements
 * Tweak – Optimized filter implementation

#### 1.0.0

 * Initial Release

## Meta

 *  Version **1.1.4**
 *  Last updated **12 jam sing kepungkur**
 *  Active installations **100+**
 *  WordPress version ** 4.7 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/turn-off-rest-api/)
 * Tags
 * [disable REST API](https://jv.wordpress.org/plugins/tags/disable-rest-api/)[JSON](https://jv.wordpress.org/plugins/tags/json/)
   [rest-api](https://jv.wordpress.org/plugins/tags/rest-api/)[security](https://jv.wordpress.org/plugins/tags/security/)
   [wp-json](https://jv.wordpress.org/plugins/tags/wp-json/)
 *  [Nonton lanjutan](https://jv.wordpress.org/plugins/turn-off-rest-api/advanced/)

## Peringkat

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/turn-off-rest-api/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/turn-off-rest-api/reviews/)

## Kontributor

 *   [ ksym04 ](https://profiles.wordpress.org/ksym04/)

## Sokong

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/turn-off-rest-api/)