How To's Wordpress

Block RESTAPI access to your WordPress site

add_filter('rest_api_init', 'rest_only_for_authorized_users', 99);

function rest_only_for_authorized_users($wp_rest_server)
{
  if (!is_user_logged_in()) {
    wp_die('REST API is blocked', 'Access denied', 403);
  }
}
Share this article

4 thoughts on “Block RESTAPI access to your WordPress site”

  1. Noah

    Shared the REST lockdown notes with WP retainer clients. Default-open interfaces feel reckless now.

  2. Juhi

    Hardening endpoints without breaking the block editor needed your exceptions list. Careful reading paid off.

  3. Kavya

    Who may hit /wp-json sat unanswered too long. Allowlist approach from this post is what we implemented.

  4. Aditya

    REST route lockdown landed on our hardening list after a noisy bot week. Access rules here are the starting template.

Leave a Reply

Your email address will not be published. Required fields are marked *