Disable REST API
by Dave McHale · Admin & Utilities
Also makes 4 other plugins · 80.1K+ installs across the portfolio →
Disable the use of the REST API on your website to site users. Now with User Role support!
53 health vs 54 average across 3,791 Admin & Utilities plugins
Removal-risk signals
28/100Maintenance and integrity signals that tend to precede a WordPress.org removal. Not an official status, a heads-up to act.
- Not actively maintained. No update in about 2 years.
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Room to improve
Biggest win: Update recency
To rank higher: Last updated 1076 days ago — ship an update; wp.org decays a listing's search weight after ~180 days.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
5.2K
now · peak 41.0K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
No release in a yearHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
0
releases in the last 12 months
2.9y ago
latest release · vv1.8
13
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 82% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “80K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-04-01 · 1,482 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Recent review vibe
read from the latest 12 reviews to 2024-08-19Reviewers keep calling it a set-and-forget install that blocks the REST API while letting chosen endpoints through, though a couple flag stale compatibility info and one site broke outright after activation.
Recent reviews
All reviews on wp.org ↗- ★★★★★ graphicvision12.0y ago
What else can I say, this plugin does exactly what its supposed to do. It’s easy to understand and works perfectly. So well done!
Read on wp.org ↗ - ★★★★★ Maarten B2.7y ago
The plugin does what it says on the tin, without being pretentious. Absolutely fantastic!
Read on wp.org ↗ - ★★★★★ ucsendre2.9y ago
I always start my WordPress installations with this plugin (among a few other ones). A must have on all sites. Thank you.
Read on wp.org ↗ - ★★★★★ mw8153713.4y ago
The plugin still works for me on WordPress 6.2. It’s great to have the option to allow API access where I need it and block everything else.
Read on wp.org ↗ - ★★★★★ Ronny Adsetts3.6y ago
Allows locking the WP API behind auth and selectively allowing it where needed. Despite the lack of plugin updates, the author does have an active github repo so don’t let that put you off.
Read on wp.org ↗ - ★★★★★ Ben Sibley3.6y ago
Blocking the REST API entirely breaks plugins that require this functionality, so being able to selectively enable routes is perfect. I recommend this plugin to everyone who uses Independent Analytics to secure their site while still enabling analytics to be recorded.
Read on wp.org ↗ - ★★★★★ Hendrik573.6y ago
This is a very good plugin with the options, and it could still work now, but we can not verify compliance. Please update. And do not forget to update the .txt file that shows tested WordPress. This topic was modified 2 years, 2 months ago by Hendrik57. Reason: New experiences This topic was modified 2 years, 2 months ago by Hendrik57.
Read on wp.org ↗ - ★★★★★ richardjwallace3.7y ago
I installed this but following install I couldn’t view any webpages. The main page give exception Notice: Trying to get property ‘name’ of non-object in /home/customer/www/XXXXXX/public_html/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php on line 60 I prompted renamed plugin folder using FTP in the folder wp-content\plugins\disable-json-api.disable so I could login then deleted it Good idea but didn’t work for my site This topic was modified 3 years, 6 months ago by richardjwallace.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 1.8 Tested up to WP v6.3 Added dra_error_message filter so devs can customize the access error message Fixed bug that caused fatal errors if activating plugin on installations running the LearnPress plugin Changed minimum re 1.8
- — Version 1.7 Tested up to WP v5.8 Replace use of filemtime() with plugin version number for static file enqueues. Props @tangrufus for bringing this up! Fixed logic bug for role-based default_allow rules. Props @msp1974 for the repor 1.7
- — Version 1.6 Tested up to WP v5.6 Added support for managing endpoint access on a per-user-role basis Soooooooo many small changes behind the scenes to support the above 1.6
- — Version 1.5.1 Tested up to WP v5.5 1.5.1
- — Version 1.5 Tested up to WP v5.3 Added enforcement for WordPress and PHP minimum version requirements Fixed minor bug to prevent unintended empty routes Minor text updates and adding textdomain to translation functions that didn’t h 1.5
- — Version 1.4.3 Added load_plugin_textdomain() for i18n 1.4.3
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 6.3.1
Languages
via translate.wordpress.orgTranslated into 19 languages, 17 at 90% or more
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-07-18 90K+ → 80K+ down after 2 days in tier
- 2026-07-16 80K+ → 90K+ up after 4 days in tier
- 2026-07-12 90K+ → 80K+ down after 1356 days in tier
- 2022-10-25 80K+ → 90K+ up after 1 days in tier
- 2022-10-24 90K+ → 80K+ down after 4 days in tier
- 2022-10-20 80K+ → 90K+ up
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Disable WP REST API 30K+ installs · 4.6★ · 4 shared tags A -
WordPress REST API (Version 2) 10K+ installs · 4.1★ · 4 shared tags D -
WP REST API – OAuth 1.0a Server 8K+ installs · 3.8★ · 4 shared tags D - W WP REST API Meta Endpoints 1K+ installs · 3.6★ · 4 shared tags D
-
Make Connector 80K+ installs · 3.1★ · 3 shared tags B
-
WPGet API – Connect to any external REST API 10K+ installs · 4.7★ · 3 shared tags A
Embed this report card
Drop a live Pulse card for Disable REST API into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/disable-json-api" width="480" height="300" style="border:0" loading="lazy" title="Disable REST API — Plugin Pulse"></iframe> Disable REST API: 80K+ active installs, 4.8★ (38 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/disable-json-api