BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Turn Off REST API icon
Actively maintained Tested with WP 7.1 #2 in disable REST API

Turn Off REST API

Disable the WordPress REST API for logged out visitors and lock down your /wp-json endpoints, with a per route allow list so you stay in control.

Active installs100+100+ tier
Downloads · 30d343▼ -13.2% vs prev. 30d
Rating—0 reviews
Health score68/100Good
All-time downloads3.8KSince Mar 2017
Support resolved—No recent threads
RequiresWP 4.7PHP 7.4+
Downloads · 7d46▼ -76.6% week over week
Our verdict

Solid choice

Turn Off REST API is a solid plugin choice in 2026, with a few things worth checking first. It runs on 100+ sites and was last updated 1 week ago, and scores 68/100 on our health check.

  • Actively developed — last update 1 week ago
  • Tested with the latest WordPress (7.1)
  • Small user base (100+ active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

4183125Jul 6Aug 19Oct 3
Yesterday9
Daily average (1y)4
Peak day167Sep 2, 2026
Last 12 months1.6K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Turn Off REST API stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
disable REST API #43 2,369 Best disable REST API plugins →
JSON >100 6,573 Best JSON plugins →
rest-api #65 7,538 Best rest-api plugins →
security >100 10,000 Best security plugins →
wp-json >100 5,836 Best wp-json plugins →

Version adoption

Share of active sites per release.

  • 1.188.5%
  • 1.011.5%

About Turn Off REST API

From the official readme · v1.1.4

Description

Turn Off REST API is a lightweight WordPress security plugin that disables the WordPress REST API for visitors who are not logged in. Anonymous requests to your /wp-json endpoints receive an authentication error instead of your site data, while logged in users, the block editor, and your admin area keep working normally.

Because every route is blocked for logged out visitors by default, features that call the REST API on behalf of visitors stop working for them until you allow their routes. This includes the WooCommerce Cart and Checkout blocks and Contact Form 7 form submissions. The FAQ below shows exactly which routes to allow.

By default WordPress exposes a large amount of information through the REST API, including your list of user accounts and usernames, published content, and details about your site. For most sites that open, unauthenticated access is unnecessary and only widens the attack surface for user enumeration and content scraping. Turn Off REST API closes the WordPress REST API to the public in one click, then gives you a clear settings screen to reopen only the specific REST API routes you actually need.

Why turn off the WordPress REST API?

  • Stop anonymous user enumeration through /wp-json/wp/v2/users.
  • Reduce your attack surface against REST API based exploits and bots.
  • Keep your content and site data from being scraped through the public API.
  • Stay in control with a per route allow list instead of an all or nothing switch.

What it does

  • Returns an authentication error for unauthenticated REST API requests.
  • Optionally removes the REST API discovery links and headers from your page source.
  • Lets you build an allow list of routes that should stay public (for example a contact form or a specific integration).
  • Adds a Site Health check so the restriction is clearly explained and never mistaken for a fault.
  • Keeps the admin area, the block editor, and logged in functionality fully working.

Built for control, not breakage

Some security plugins disable the REST API completely and break the block editor or third party integrations in the process. Turn Off REST API only blocks unauthenticated access, and the per route allow list means you can whitelist exactly the endpoints a service needs without opening the whole API back up.

Developer friendly

The access decision runs through the tora_grant_rest_api filter, so developers can extend or override the logic for custom roles, application passwords, or trusted requests.

Installation

  1. In your WordPress admin, go to Plugins, then Add New.
  2. Search for “Turn Off REST API”.
  3. Click Install Now, then Activate.
  4. Go to Settings, then Turn Off REST API to review the route allow list. Unauthenticated access is disabled by default. If your site uses the WooCommerce Cart or Checkout blocks or Contact Form 7, allow their routes as described in the FAQ.

Manual installation:

  1. Download the plugin zip from WordPress.org.
  2. Upload the turn-off-rest-api folder to /wp-content/plugins/.
  3. Activate the plugin through the Plugins menu in WordPress.

Frequently asked questions

How do I confirm the REST API is blocked?

Log out of your site (or open a private browser window) and visit https://your-site.com/wp-json. You should see an authentication error instead of a list of routes and data. Logged in users will still see the normal response.

Will this break the block editor (Gutenberg)?

No. The block editor runs as a logged in user, so it keeps full REST API access. Only unauthenticated requests are blocked.

I need one endpoint to stay public. Can I allow just that route?

Yes. Open Settings, then Turn Off REST API, check the route or namespace you want to keep open, and save. Everything else stays blocked.

My WooCommerce cart or checkout, or my Contact Form 7 form, stopped working for visitors. How do I fix it?

These features send REST API requests on behalf of logged out visitors, and the plugin blocks every route for visitors until you allow it. The WooCommerce Cart and Checkout blocks use the routes under /wc/store/v1. Contact Form 7 sends each form submission through its own routes under /contact-form-7/v1. Go to Settings, then Turn Off REST API. Under Allowed REST API Routes, find the /wc/store/v1 heading and check its box. This also checks every route listed under it. The separate /wc/store heading above it is not used by the blocks. For Contact Form 7, find the /contact-form-7/v1 heading and…

Does it work on nginx as well as Apache?

Yes. The plugin works at the WordPress request level and does not depend on any web server configuration files.

Can developers customize who is allowed?

Yes. Use the tora_grant_rest_api filter to return true or false based on your own logic. By default it returns whether the current user is logged in.

Changelog

Security fix: if another security rule had already blocked a REST API request from a visitor, this plugin could lift that block. Also removes the REST API link from page headers as the option promises. Updating is recommended.

1.1.4

  • Tested with WordPress 7.1.2.
  • Fixed – security: when another security plugin or your own code had already blocked a REST API request from a logged out visitor, this plugin could lift that block and let the request through. The earlier block is now always kept.
  • Fixed – the option to hide REST API discovery links and headers now also removes the REST API link that WordPress sends in the headers of every page. Before, only the links in the page source were removed.
  • Fixed – the settings screen no longer stops with an error when a save request contains malformed route data. Such a request is treated like one with no routes ticked.
  • Tweak – removed support code for WordPress versions older than 4.7, which the plugin already required.

1.1.3

  • Fixed – WordPress 6.7 and newer logged a “translation loading was triggered too early” notice for this plugin on sites with debugging enabled. The plugin name was being translated while the plugin loaded, before WordPress is ready to serve translations.
  • Tweak – the version used to cache bust the settings screen assets now comes from a single source, so it can never fall out of step with the plugin version again.
  • No change to how the REST API is protected.

1.1.2

  • Tested with WordPress 7.1.
  • Fixed – a PHP notice on PHP 8.2 and newer, caused by a plugin property being created on the fly instead of being declared. On a future PHP 9 this would have stopped the plugin from loading.
  • Fixed – the settings screen stylesheet and script were still labelled with the previous version number, so browsers could keep serving the old cached files after an update.
  • No change to how the REST API is protected.

1.1.1

  • New – A “More on DopeThemes” panel on the settings screen with free plugins, code snippets, themes, and tutorials. No change to how the REST API is protected.

1.1.0

  • New – Site Health check that confirms the REST API is intentionally restricted, so it is never mistaken for an error.
  • New – Option to show or hide the REST API discovery links and headers in your page source.
  • Tweak – Clearer settings screen with a protection status and a dedicated options section.

1.0.5

  • Tweak – Confirmed compatibility with WordPress 7.0.
  • Fix – PHP 8 compatibility: resolved an undefined array key warning during REST route detection.
  • Fix – Hardened output escaping on the settings screen.
  • Fix – Corrected the internationalization of the authentication error message.
  • Tweak – Added Requires PHP header and refreshed the plugin documentation.

Full changelog on WordPress.org →

Screenshots

A logged out visitor opening /wp-json gets an authentication error (status 401) instead of your site data.
A logged out visitor opening /wp-json gets an authentication error (status 401) instead…

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Turn Off REST API alternatives

All disable REST API plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 WPControl – The Easiest Optimization Plugin for WordPress WPControl – The Easiest Optimization Plugin for WordPress The easiest way to improve your website's security, performance, and user experience. by Syed Balkhi 200+ ★★★★★★★★★★ 4.5 (2) 4 years ago 32
3 MaxtDesign REST API Control MaxtDesign REST API Control Full control over your WordPress REST API. Block, restrict, or whitelist endpoints per user… by MaxtDesign 10+ ★★★★★★★★★★ No reviews 3 weeks ago 66
4 Server Response Server Response Поможет вам скорректировать заголовки ответа сервера и отключить REST API. by seoriver 10+ ★★★★★★★★★★ No reviews 9 years ago 23
5 WPBuoy Endpoint Manager WPBuoy Endpoint Manager View, search, filter, and disable WordPress REST API endpoints. Reduce your attack surface… by Martin Cipriano 10+ ★★★★★★★★★★ 5 (1) 3 weeks ago 73
6 Caledros Helper Caledros Helper Adds an Admin Menu that allows removing the default block patterns. It also allows… by David Arnado <10 ★★★★★★★★★★ No reviews 5 months ago 49
7 RestArmor Security RestArmor Security Advanced security suite. Blocks REST API, disables XML-RPC, prevents user enumeration, and… by Md. Rakib Ullah <10 ★★★★★★★★★★ No reviews 8 months ago 36
8 Disable Settings For WP Disable Settings For WP Disable Settings For WP is a WordPress plugin that allows you to disable right-click… by Harsh Gajipara <10 ★★★★★★★★★★ No reviews 2 years ago 21
9 Disable Services Manager Disable Services Manager A powerful tool is available to help you disable unused services on your site, providing… by Mayur Prajapati <10 ★★★★★★★★★★ No reviews 2 years ago 21

FAQ

Turn Off REST API: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 4, 2026

Is Turn Off REST API free?

Yes. Turn Off REST API is free to download and use from the official WordPress.org plugin directory.

Is Turn Off REST API safe to use in 2026?

Turn Off REST API is a solid plugin choice in 2026, with a few things worth checking first. It runs on 100+ sites and was last updated 1 week ago, and scores 68/100 on our health check.

How many websites use Turn Off REST API?

Turn Off REST API is active on 100+ WordPress websites and has been downloaded 3,820 times since it launched in March 2017. It was downloaded 343 times in the last 30 days.

Does Turn Off REST API work with WordPress 7.1?

Yes. The developer has tested Turn Off REST API up to WordPress 7.1.2, the latest release. It requires WordPress 4.7 or newer.

What PHP version does Turn Off REST API need?

Turn Off REST API requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Turn Off REST API last updated?

The latest version, 1.1.4, was released on September 24, 2026 (1 week ago).

Who makes Turn Off REST API?

Turn Off REST API is developed and maintained by ksym04.

What are the best alternatives to Turn Off REST API?

The most popular alternatives to Turn Off REST API are WPControl (200+ installs), MaxtDesign REST API Control (10+ installs) and Server Response (10+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.