{"id":18655726,"date":"2025-09-25T06:54:50","date_gmt":"2025-09-25T06:54:50","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/securing-the-rest-api\/"},"modified":"2025-09-25T06:54:50","modified_gmt":"2025-09-25T06:54:50","slug":"securing-the-rest-api","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/securing-the-rest-api\/","title":{"rendered":"Securing the REST API"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">This plugin requires the REST API To be enabled in order to work. This creates a security issue since with an open REST API, anyone can use the REST API and potentially attack your server. Can you kindly advise what is the best way to secure your WordPress site for attacks against REST API when using your plugin. Which REST API Authentication and protection plugin should we use and how to configure it. <br \/><br \/>We tried adding a script to make your plugin work with the famouns <a href=\"https:\/\/wordpress.org\/plugins\/disable-wp-rest-api\/\">Disable REST API plugin<\/a>, but its not possible to whitelist the paths required in your plugin since you are opening too many endpoints and its impossible to whitelist them all. <br \/><br \/>This is important. Please advise. <\/p>\n","protected":false},"template":"","class_list":["post-18655726","topic","type-topic","status-publish","hentry","topic-tag-api","topic-tag-rest","topic-tag-whitelisting"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18655726","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18655726\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=18655726"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}