On This Page
On This Page
Disable REST API
Overview
Restrict access to the WordPress REST API when your website does not need to expose core REST endpoints publicly.
Disable REST API gives you two levels of protection. The recommended Disable Public Access Only mode blocks anonymous access to WordPress core REST routes while keeping REST functionality available to logged-in users and leaving third-party namespaces alone. For highly controlled environments, Disable Completely can block REST access for everyone.
The module also removes common REST API discovery links from the frontend, giving you more control over how WordPress exposes its REST interface without requiring custom code.
Disable REST API is a Free security module in WP PowerSuite.

- Site owners who do not need WordPress core REST data exposed publicly
- Agencies hardening client websites while keeping normal editor functionality
- Business websites that do not rely on anonymous core REST API access
- Developers who want to restrict core REST without automatically blocking plugin APIs
- Security-conscious administrators who need stronger REST controls for private environments
Features
Restrict Public REST API Access
Keep Third-Party APIs Available
Completely Disable REST When Required
Protect Core WordPress Namespaces
Remove REST Discovery
Developer Route Controls
Use Cases
- Restrict Anonymous WordPress REST AccessBlock public access to WordPress core REST endpoints while keeping them available to logged-in administrators and editors.
- Reduce User EnumerationRestrict anonymous access to core REST user endpoints as part of a broader WordPress account-hardening strategy.
- Harden Business WebsitesReduce unnecessary public WordPress API exposure on sites that do not use anonymous core REST functionality.
- Preserve WooCommerce & Plugin APIsUse public-only mode when core REST should be restricted but third-party namespaces still need to operate.
- Lock Down Controlled EnvironmentsUse Disable Completely on specialized installations where REST is intentionally unavailable and compatibility has been reviewed.
- Combine With Author ProtectionUse Disable Author Archives or Hide Author URLs alongside REST restrictions when you also want greater control over public WordPress author exposure.
Frequently Asked Questions
What does Disable REST API do?
It lets you restrict anonymous access to WordPress core REST endpoints or completely disable REST access for everyone.
What is the recommended mode?
Disable Public Access Only is the default and generally the safer option because authenticated WordPress functionality continues to have REST access.
What happens to anonymous visitors in public-only mode?
Requests to protected WordPress core REST routes are denied with an authentication-required REST response, normally using HTTP 401 where appropriate.
Can logged-in users still use REST?
Yes, in Disable Public Access Only mode. Authenticated users retain full REST access.
Does it block WooCommerce REST endpoints?
Not in the default public-only mode simply because they are REST endpoints. Third-party namespaces are deliberately left separate from WordPress core namespaces.
Does it block form and membership plugin APIs?
Public-only mode does not automatically block third-party namespaces. Their own authentication and access rules continue to apply.
What does Disable Completely do?
It blocks REST access for both anonymous and logged-in users unless a developer explicitly allows a route through the provided filter.
Can Disable Completely break WordPress?
It can break REST-dependent functionality. This may include the Block Editor, Site Editor, media workflows, mobile apps, and plugin functionality.
Does the module remove REST discovery links?
Yes, when discovery removal is enabled. It can remove REST references from the frontend HTML head, HTTP Link header, oEmbed discovery, and relevant RSD output.
Does hiding REST discovery secure the API by itself?
No. Removing discovery makes the endpoints less prominently advertised, but the actual security control is the access restriction applied to REST requests.
Does it help prevent REST user enumeration?
Yes. Public mode restricts WordPress core REST endpoints, including the relevant core user routes.
How does it work with Disable Author Archives?
Disable Author Archives recognizes when Disable REST API is enabled and avoids duplicating its own REST users protection.
How does it work with Hide Author URLs?
The same applies to Hide Author URLs. This module handles the core REST restriction while Hide Author URLs focuses on the public author URL structure.
Does it disable XML-RPC?
No. Disable XML-RPC is a separate security control.
Does it disable WordPress Application Passwords?
No. Application Passwords are a separate feature and are not disabled by this module.
Can developers allow specific REST routes?
Yes. Developer filters are available for customizing core namespaces, anonymous route handling, and explicit exceptions to complete-disable mode.
Can I see the REST status elsewhere in WP PowerSuite?
Yes. System Summary can report whether REST API access is publicly restricted or completely disabled.
Does the module require WP PowerSuite Pro?
No. Disable REST API is a Free module included with WP PowerSuite and continues operating without a Pro license.


