BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Batch REST Guard icon
Actively maintained Tested up to 7.0.7 #1 in exploit

Batch REST Guard

Block wp2shell REST batch attacks (CVE-2026-63030). Detect fake admins and backdoor plugins. Extra security for hacked sites.

Active installs100+100+ tier
Downloads · 30d183▼ -31.7% vs prev. 30d
Rating—0 reviews
Health score59/100Fair
All-time downloads446Since Aug 2026
Support resolved—No recent threads
RequiresWP 4.1PHP 7.2+
Downloads · 7d53▲ +35.9% week over week
Our verdict

Use with caution

Batch REST Guard works, but test it on a staging site before relying on it in 2026. It runs on 100+ sites and was last updated 2 months ago, and scores 59/100 on our health check.

  • Small user base (100+ active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

132639Aug 10Sep 8Oct 8
Yesterday5
Daily average (1y)8
Peak day52Aug 10, 2026
Last 12 months451

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Batch REST Guard stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
exploit #19 254 Best exploit plugins →
hacked #11 140 Best hacked plugins →
malware #73 431 Best malware plugins →
rest-api #46 7,709 Best rest-api plugins →
security >100 10,000 Best security plugins →

Version adoption

Share of active sites per release.

  • 1.2100.0%

About Batch REST Guard

From the official readme · v1.2.5

Description

Was your site hacked? Did you get a “password changed” email without requesting a reset? You may be a victim of the wp2shell attack — one of the most serious security issues in recent years.

Batch REST Guard is a free security plugin that protects your website from the wp2shell exploit chain (CVE-2026-63030 + CVE-2026-60137). Attackers use this vulnerability to break into sites without a password, create hidden administrator accounts, install backdoor plugins, and change your admin password — all through the REST API batch endpoint.

What does this plugin do?

  • Blocks the attack entry point — stops unauthenticated requests to /wp-json/batch/v1 and ?rest_route=/batch/v1 (including POST body bypasses that fool some WAF rules).
  • Keeps your site working — logged-in users and the block editor (Gutenberg) continue to work normally.
  • Blocks known exploit tools — rejects requests from automated wp2shell scanners.
  • Alerts you if core is still vulnerable — reminds you to update to 6.8.6, 6.9.5, 7.0.2 or later.
  • Finds signs of an existing hack — warns about suspicious admin users (w2s_*, wp2_*, wpsvc_*) and fake plugins (site-tweaks-…, admin-utils-…, content-tools-… and similar random names).

Who should install this?

  • Site owners affected by the wp2shell / batch REST vulnerability.
  • Anyone who cannot update core immediately and needs a temporary security fix.
  • Agencies and hosts managing multiple client sites.
  • Sites behind Cloudflare or another WAF — use both; this plugin blocks attacks inside the application where edge rules may miss POST-body bypasses.

What is wp2shell?

Wp2shell is an unauthenticated remote code execution (RCE) attack against the WordPress REST API batch endpoint. It was actively exploited in the wild in 2026. Attackers can:

  • Create rogue administrator accounts (often named w2s_… or wp2_…).
  • Upload webshell plugins with innocent-looking names.
  • Change existing admin passwords (you receive a “password changed” email).
  • Take full control of your site without ever logging in.

Updating core is the complete fix. This plugin adds an essential extra layer and helps you spot leftover malware after a cleanup.

Compatible with

  • All hosting environments (shared, VPS, dedicated).
  • Cloudflare, Patchstack, Wordfence and other security tools (works alongside them).
  • PHP 7.2+ and WordPress 4.1+.
  • Multisite and single-site installations.

Developed by 365dizajn — web design and hosting security.

Installation

  1. Upload the plugin files to /wp-content/plugins/batch-rest-guard/, or install through Plugins → Add New → Upload Plugin.
  2. Click Activate.
  3. Check the Plugins screen — you should see Core OK — guard active.
  4. If you see red admin warnings, follow the instructions (update core, delete suspicious users/plugins).

No configuration required. Protection starts immediately after activation.

Frequently asked questions

My admin password was changed and I did not request a reset. Can this help?

Yes. That is a common sign of the wp2shell attack. Install this plugin, update core immediately, delete any unknown admin users, and remove suspicious plugins. The plugin will alert you to known indicators of compromise.

Do I still need this if core is already updated?

Yes, as an extra layer. On 6.8.6 / 6.9.5 / 7.0.2 or newer, core is patched. The plugin still blocks anonymous batch requests and can alert you to leftover malicious admin users or fake plugins from a previous attack.

Will this break the block editor (Gutenberg)?

No. Logged-in users can still use the batch API. Only unauthenticated (anonymous) requests are blocked.

I use Cloudflare WAF rules. Is this plugin still needed?

Yes. Some early WAF rules only checked the URL, but attackers can send rest_route=/batch/v1 in the POST body. This plugin blocks that inside WordPress regardless of your WAF.

Does this replace Wordfence or a security plugin?

No. It complements them. Batch REST Guard focuses specifically on the wp2shell / REST batch attack vector. Keep your main security plugin and keep core updated.

What suspicious users and plugins does it detect?

Administrator accounts starting with w2s_, wp2_, or wpsvc_, attacker email domains, and plugin folders matching known fake utility names or random hex suffixes (for example site-tweaks-ab4378ea9c).

Changelog

Improved description and FAQ. No code changes — safe to update.

1.2.5

  • Removed Plugin URI header (same as Author URI — WordPress.org submission requirement).

1.2.4

  • Short description trimmed to 150 characters (WordPress.org readme requirement).

1.2.3

  • Expanded plugin description and FAQ for better discoverability and clearer use cases.

1.2.2

  • Renamed plugin to Batch REST Guard (WordPress.org trademark compliance).
  • Slug changed to batch-rest-guard.
  • Requires at least WordPress 4.1 (wp_json_encode compatibility).
  • Plugin Check fixes: error_log phpcs ignore, ZIP paths.

1.2.1

  • Fixed ZIP packaging for Linux servers.

1.2.0

  • First public release (as wp2shell-guard).

Full changelog on WordPress.org →

Screenshots

Plugin active on the Plugins screen with core status.
Plugin active on the Plugins screen with core status.

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Batch REST Guard alternatives

All exploit plugins →

FAQ

Batch REST Guard: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 9, 2026

Is Batch REST Guard free?

Yes. Batch REST Guard is free to download and use from the official WordPress.org plugin directory.

Is Batch REST Guard safe to use in 2026?

Batch REST Guard works, but test it on a staging site before relying on it in 2026. It runs on 100+ sites and was last updated 2 months ago, and scores 59/100 on our health check.

How many websites use Batch REST Guard?

Batch REST Guard is active on 100+ WordPress websites and has been downloaded 446 times since it launched in August 2026. It was downloaded 183 times in the last 30 days.

Does Batch REST Guard work with WordPress 7.1?

Batch REST Guard is officially tested up to WordPress 7.0.7, while the latest release is 7.1.3. It may still work, but try it on a staging site first.

What PHP version does Batch REST Guard need?

Batch REST Guard requires PHP 7.2 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Batch REST Guard last updated?

The latest version, 1.2.5, was released on August 10, 2026 (2 months ago).

Who makes Batch REST Guard?

Batch REST Guard is developed and maintained by vladanrs.

What are the best alternatives to Batch REST Guard?

The most popular alternatives to Batch REST Guard are WP-Sentinel (60+ installs), Gauntlet Security (50+ installs) and WP Smart Security (20+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.