PluginSift
PluginsThemesCompare
Directory
  • Plugins
  • Themes
  • Compare Plugins
Plugin Comparisons
  • SEO
  • Security
  • Ecommerce
  • Page Builders
  • Caching
  • Backup
  • Forms
  • Analytics
Resources
  • About
  • Contact
  • llms.txt

© 2026 PluginSift. Data sourced from WordPress.org. · [email protected]

  1. Home
  2. Plugins
  3. Rest
  4. Pinny’s REST Lock – Block REST User…
Pinny’s REST Lock – Block REST User Enumeration icon

Pinny’s REST Lock – Block REST User Enumeration

Prevents public access to REST API user endpoints while allowing authorized roles.

By Pinny Fried·Rest·Free
00
·10 active installs·Updated 1 month ago
DownloadVisit HomepageCompare

As of April 2026, Pinny’s REST Lock is a WordPress rest plugin with 10 active installations and a 0/5 rating0. It has been downloaded 187 times in total. Requires WordPress 5.0+ and PHP 7.0+. Available on WordPress.org since 2026. Actively maintained — updated within the last month. Top alternative: Disable REST API.

0/5Rating
10active installs
187total downloads
3 monthssince 2026

Overview

Blocks public REST API user enumeration while preserving full WordPress functionality.

Pinny’s REST Lock is an ultra-lightweight security plugin that locks down WordPress REST API user endpoints without breaking your site.

It is designed to fix one of the most common and overlooked WordPress security issues — public user enumeration via the REST API — using the correct, core-aligned approach.

🚨 Why This Plugin Is Necessary

By default, WordPress publicly exposes REST API endpoints such as:

/wp-json/wp/v2/users

On public sites, these endpoints can be accessed without authentication and are routinely used as the first step in real-world attacks.

This is where attackers start.

Public access to REST user endpoints allows attackers to:

  • Enumerate valid usernames
  • Identify administrator and pri…
Read full description on WordPress.org

Ratings & Reviews

00 reviews
5 ★
0
4 ★
0
3 ★
0
2 ★
0
1 ★
0

Compatibility

WordPress5.0+ requiredTested up to 6.9.4
PHP7.0+ required

Top Alternatives to Pinny’s REST Lock – Block REST User…

Disable REST API icon
Disable REST API
4.890K+ installsUpdated 2 years ago
ViewCompare
Make Connector icon
Make Connector
2.780K+ installsUpdated 1 month ago
ViewCompare
Disable WP REST API icon
Disable WP REST API
4.830K+ installsUpdated 1 week ago
ViewCompare
JWT Authentication for WP REST APIs icon
JWT Authentication for WP REST APIs
4.420K+ installsUpdated 1 month ago
ViewCompare
WordPress REST API (Version 2) icon
WordPress REST API (Version 2)
4.210K+ installsUpdated 8 years ago
ViewCompare
View all rest plugins →

Frequently Asked Questions

Changelog

1.0.0

  • Initial release
View full changelog on WordPress.org

Contributors

Pinny FriedPinny Fried
Plugin Info
Version
1.0.0
Last Updated
Mar 6, 2026
WP Requires
5.0+
Tested Up To
6.9.4
PHP Requires
7.0+
Active Installs
10
Downloads
187
Added
Jan 25, 2026
Business
Free

Tags

restusersno-bloatsecurityenumeration

Developer

P
Pinny Fried
3 plugins0.0M+ total installs
View all plugins →

Quick Compare

Pinny’s REST Lock – Block REST User… vs Disable REST API→Pinny’s REST Lock – Block REST User… vs Make Connector→Pinny’s REST Lock – Block REST User… vs Disable WP REST API→

Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.