外掛說明
This plugin does one thing: disables the WP REST API for visitors who are not logged into WordPress. No configuration required.
This plugin works with only 22 short lines of code (less than 2KB). So it is super lightweight, fast, and effective.
Features
- Disable REST/JSON for visitors (not logged in)
- Disables REST header in HTTP response for all users
- Disables REST links in HTML head for all users
- 100% plug-and-play, set-it-and-forget solution
The fast, simple way to prevent abuse of your site’s REST/JSON API
How does it work? That depends on which version of WordPress you are using..
WordPress v4.7 and beyond
For WordPress 4.7 and better, this plugin completely disables the WP REST API unless the user is logged into WordPress.
- For logged-in users, WP REST API works normally
- For logged-out users, WP REST API is disabled
What happens if logged-out visitor makes a JSON/REST request? They will get only a simple message:
“rest_login_required: REST API restricted to authenticated users.”
This message may customized via the filter hook, disable_wp_rest_api_error
. Check out this post for an example of how to do it.
Older versions of WordPress
For WordPress versions less than 4.7, this plugin simply disables all REST API functionality for all users.
More information available below in the FAQs section.
隱私權
This plugin does not collect or store any user data. It does not set any cookies, and it does not connect to any third-party locations. Thus, this plugin does not affect user privacy in any way. If anything it improves user privacy, as it protects potentially sensitive information from being displayed/accessed via REST API.
Disable WP REST API 由具備 15 年 WordPress 開發者及書籍作者經驗的 Jeff Starr 開發及維護。
支持這個外掛的開發工作
因為喜愛 WordPress 社群,因此我開發並維護這個免費外掛。如果想要支持外掛開發工作,請贊助開發工作或購買我撰寫的書籍:
- The Tao of WordPress
- Digging into WordPress
- .htaccess made easy
- WordPress Themes In Depth
- Wizard’s SQL Recipes for WordPress
也可以透過購買以下付費 WordPress 外掛支持外掛開發:
- BBQ Pro:效能極佳的 WordPress 防火牆
- Blackhole Pro:自動封鎖惡意漫遊器
- Banhammer Pro:監控網路流量及封鎖惡意存取
- GA Google Analytics Pro:將 WordPress 網站連接至 Google Analytics
- Simple Ajax Chat Pro:沒有限制的聊天室
- USP Pro:沒有限制的網站前端功能表單
十分歡迎外部連結、轉推及按讚,謝謝大家 🙂
安裝方式
How to Install
- Upload the plugin to your blog and activate
- Done! No further configuration is required.
More info on installing WP plugins
Testing
To test that the plugin is working, log out of WordPress and then request https://example.com/wp-json/
in a browser. See FAQs for more infos.
Like the plugin?
If you like Disable WP REST API, please take a moment to give a 5-star rating. It helps to keep development and support going strong. Thank you!
常見問題集
-
What is the default access-denied message?
-
When the user is logged in to WordPress, the normal REST API data will be displayed. When the user is not logged in, this is the default message:
{"code":"rest_login_required","message":"REST API restricted to authenticated users.","data":{"status":401}}
-
Why would anyone want to disable the REST API?
-
Technically this plugin only disables REST API for visitors who are not logged into WordPress. With that in mind, here are some good reasons why someone would want to disable REST API for non-logged users:
- The REST API may not be needed for non-logged users
- Disabling the REST API conserves server resources
- Disabling the REST API minimizes potential attack vectors
- Disabling the REST API prevents content scraping and plagiarism
I’m sure there are other valid reasons, but you get the idea 🙂
-
There already is another “Disable REST” plugin?
-
Yep, actually there are two other “Disable REST” plugins:
The first of those plugins is awesome and provides a LOT more features and functionality than is required to simply disable REST. And the second plugin was shut down due to lack of use. I wrote my disable-REST plugin because I wanted something super lightweight, fast, and effective. If you are looking for more options and features, then check out the first of those two listed alternatives.
-
How do I test that REST is disabled?
-
Testing is easy:
- Log out of WordPress
- Using a browser, request
https://example.com/wp-json/
If you see the following message, REST is disabled:
“rest_login_required: REST API restricted to authenticated users.”
Then if you log back in and make a new request for
https://example.com/wp-json/
, you will see that REST is working normally. -
Does it disable REST functionality added by other plugins?
-
Yes, if the REST endpoints are registered with the WP REST API.
-
Does this work with Gutenberg/Block Editor?
-
Yes. It works the same regardless of which editor (Classic or Block) you are using.
-
How to customize the error message?
-
By default the plugin displays a message for unauthenticated users: “REST API restricted to authenticated users.” To customize that message to whatever you want, add the following code via functions.php or simple custom plugin:
function disable_wp_rest_api_error_custom($message) { return 'Customize your message here.'; // change this to whatever you want } add_filter('disable_wp_rest_api_error', 'disable_wp_rest_api_error_custom');
-
How to allow access for Contact Form 7?
-
As explained in this thread, the plugin Contact Form 7 requires REST API access in order for the contact form to work. To allow for this, follow this guide.
-
如何提問?
-
Send any questions or feedback via my contact form
使用者評論
參與者及開發者
變更記錄
If you like Disable WP REST API, please take a moment to give a 5-star rating. It helps to keep development and support going strong. Thank you!
2.5.1
- Fixes incorrect variable name
- Tests on WordPress 6.2
2.5
- Adds functionality to whitelist
$_SERVER
vars - Adds functionality to allow for array of vars
- Updates default translation template
- Tests on WordPress 6.1 + 6.2 (beta)
- Tests on PHP 8.1 and 8.2
2.4.1
- Improves plugin documentation
- Tests on WordPress 6.1
2.4
- Tests on WordPress 6.0
2.3
- Improves documentation
- Updates some links to external resources
- Changes minimum required WP version to 4.6
- Tests on WordPress 5.9
2.2
- Tests on WordPress 5.8
2.1
- Adds support for CF7 (Thanks to @darko-a7) (more info)
- Adds filter hook
disable_wp_rest_api_post_var
- Tests on PHP 7.4 and 8.0
- Tests on WordPress 5.7
2.0
- Tests on PHP 7.4 and 8.0
- Tests on WordPress 5.6
1.9
- Refines readme/documentation
- Tests on WordPress 5.5
1.8
- Tests on WordPress 5.4
1.7
- Tests on WordPress 5.3
1.6
- Updates some links to https
- Tests on WordPress 5.3 (alpha)
1.5
- Bumps minimum PHP version to 5.6.20
- Tests on WordPress 5.2
1.4
- Tests on WordPress 5.1 and 5.2 (alpha)
1.3
- Tests on WordPress 5.1
1.2
- Adds homepage link to Plugins screen
- Updates default translation template
- Tests on WordPress 5.0
1.1
- Updates GDPR blurb and donate link
- Adds “rate plugin” link to Plugins screen
- Adds icons for the WordPress Plugin Directory
- Generates default translation template
- Further tests on WP versions 4.9 and 5.0 (alpha)
1.0
- Initial release