Block RESTAPI access to your WordPress site
add_filter('rest_api_init', 'rest_only_for_authorized_users', 99);
function rest_only_for_authorized_users($wp_rest_server)
{
if (!is_user_logged_in()) {
wp_die('REST API is blocked', 'Access denied', 403);
}
}
Share this article

Shared the REST lockdown notes with WP retainer clients. Default-open interfaces feel reckless now.
Hardening endpoints without breaking the block editor needed your exceptions list. Careful reading paid off.
Who may hit /wp-json sat unanswered too long. Allowlist approach from this post is what we implemented.
REST route lockdown landed on our hardening list after a noisy bot week. Access rules here are the starting template.