Hi @winner-singh,
This looks like an attempt to discover usernames via the oEmbed API.
In order to block this kind of attacks we recommend that you keep the “Prevent discovery of usernames through […]“ option enabled.
Please have a look at this post on our blog to learn more about username harvesting.
I think my blog is secure because when I check via this way: wp-json/wp/v2/users
https://www.allinallnews.com/wp-json/wp/v2/users It shows: Sorry, you are not allowed to list users.”,”data”:{“status”:401}}
but when I checked some other blogs who have good Alexa ranking, they have problems
https://www.shoutmeloud.com/wp-json/wp/v2/users
https://hellboundbloggers.com/wp-json/wp/v2/users
https://www.labnol.org/wp-json/wp/v2/users
But I hope this will not reduce my blog traffic.
Like I said someone search URL in this way:
https://allinallnews.com/wp-json/oembed/1.0/embed?url=http%253A%252F%252Fallinallnews.com%252Fentertainment%252Frustom-must-watch-movie-year
so should I use this option “Immediately block IPs that access these URLs”
and block url in this way
/wp-json/wp/v2/users/
/threaten.php/
suggest me more URLs so that I can add to option “Immediately block IPs that access these URLs”
Hi @winner-singh,
Sorry about the delayed response.
It’s very unlikely that Google would index or use the WordPress REST API so I don’t think blocking IPs that access “/wp-json/wp/v2/users/” could affect your rankings.
As a general advice, the option “Prevent discovery of usernames […]” should be enough to protect your site against those type of attacks.
Adding that URL to the banned URLs might help if you get a very large amount of requests for it.