PluginSift
PluginsThemesCompare
Directory
  • Plugins
  • Themes
  • Compare Plugins
Plugin Comparisons
  • SEO
  • Security
  • Ecommerce
  • Page Builders
  • Caching
  • Backup
  • Forms
  • Analytics
Resources
  • About
  • Contact
  • llms.txt

© 2026 PluginSift. Data sourced from WordPress.org. · [email protected]

  1. Home
  2. Plugins
  3. Headless
  4. Headless REST API Security
Headless REST API Security icon

Headless REST API Security

Manage access to the WordPress REST API by restricting public endpoints, enabling specific route allow-listing, and handling API key authentication.

By Md. Rakib Ullah·Headless·Free
5(2 reviews)
·20 active installs·Updated 1 month ago
DownloadVisit HomepageCompare

As of April 2026, Headless REST API Security is a WordPress headless plugin with 20 active installations and a 5/5 rating from 2 reviews. It has been downloaded 333 times in total. Requires WordPress 5.8+ and PHP 7.4+. Available on WordPress.org since 2026. Recently updated within the last 3 months. Top alternative: WPGraphQL.

5/52 reviews
20active installs
333total downloads
3 monthssince 2026

Overview

Running a Headless WordPress site often involves exposing the REST API. Headless REST API Security provides tools for administrators to control which endpoints are accessible to the public or external applications.

This plugin restricts public access to REST API endpoints by default and offers a settings interface to allow-list only the specific routes required by a frontend application (such as Next.js, Gatsby, or mobile apps).

Features

  • Access Control: Restrict default public access to REST API endpoints.
  • Route Allow-Listing: Specific API routes (e.g., /wp/v2/posts) can be enabled while others remain restricted.
  • API Key Authentication: Supports an X-API-KEY header for server-to-server or frontend requests.
  • Headless Redirect: Option to redirect users accessing the backend API URL to a sp…
Read full description on WordPress.org

Screenshots

Ratings & Reviews

52 reviews
5 ★
2
4 ★
0
3 ★
0
2 ★
0
1 ★
0

Compatibility

WordPress5.8+ requiredTested up to 6.9.4
PHP7.4+ required

Top Alternatives to Headless REST API Security

WPGraphQL icon
WPGraphQL
4.930K+ installsUpdated 2 weeks ago
ViewCompare
WPGraphQL for ACF icon
WPGraphQL for ACF
510K+ installsUpdated 4 weeks ago
ViewCompare
Headless Mode icon
Headless Mode
52.0K+ installsUpdated 1 year ago
ViewCompare
Faust.js icon
Faust.js
51.0K+ installsUpdated 1 year ago
ViewCompare
CoCart – Headless REST API for WooCommerce icon
CoCart – Headless REST API for…
4.91.0K+ installsUpdated 2 months ago
ViewCompare
View all headless plugins →

Frequently Asked Questions

Changelog

2.3

  • Fix: Resolved a critical error on the settings page caused by third-party plugin conflicts with REST API initialization.
  • Fix: Resolved stable tag and version mismatch issues for WordPress.org compliance.
View full changelog on WordPress.org

Contributors

Md. Rakib UllahMd. Rakib Ullah
Plugin Info
Version
2.2
Last Updated
Feb 22, 2026
WP Requires
5.8+
Tested Up To
6.9.4
PHP Requires
7.4+
Active Installs
20
Downloads
333
Added
Jan 20, 2026
Business
Free

Tags

headlessrest-apipermissionsaccess-controlauthentication

Developer

M
Md. Rakib Ullah
2 plugins0.0M+ total installs
View all plugins →

Quick Compare

Headless REST API Security vs WPGraphQL→Headless REST API Security vs WPGraphQL for ACF→Headless REST API Security vs Headless Mode→

Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.