SMNTCS Disable REST API User Endpoints icon

SMNTCS Disable REST API User Endpoints

by Niels Lange

View on WordPress.org
71 Quality Score
Active Installs
17/30

At 7,000 active installs the plugin has modest reach, which lifts the score above the raw install number would suggest because the category is narrow.

Update Freshness
25/25

The plugin was last updated on 2024-12-31 and is tested against WordPress 6.7.5, but it has gone years with only one author and minimal change activity, so sustained support is hard to predict.

User Rating
6/15

Two perfect ratings give a 100/100 score, though with such a small sample the result is statistically weak and should not be over-trusted.

Support Health
8/15

Zero support threads opened and zero resolved means there is no public track record of help, raising questions about how the author responds when something goes wrong.

WP Compatibility
15/15

It requires WordPress 5.5 and PHP 5.6, which covers virtually every current site, but no WooCommerce, block editor, or multisite testing is documented.

Scores higher than 25% of indexed plugins

About

Hides the list of user accounts that the WordPress REST API shows to visitors who are not logged in, which helps prevent user enumeration.

Active Installs 8k+
Rating ★★★★★ 5/5
Last Updated 2026-09-26 4:13am GMT
Requires WordPress 5.5+
Tested Up To 7.1.2
Requires PHP 5.6+
✓ No known vulnerabilities

What It Does

SMNTCS Disable REST API User Endpoints blocks the WordPress REST API user endpoints, which can otherwise expose usernames and other user data when guessed or discovered through public author archives. Once activated, requests to those endpoints return nothing useful, closing off an obscure but real information-disclosure vector. It is a single-purpose plugin with no settings screen and no broader security features.

Who It's For

This plugin suits site owners who are concerned about user enumeration via the REST API, especially on multi-author blogs, membership sites, or any community where revealing author slugs could expose credentials or sensitive content. It is small, lightweight, and ideal for users who only want to fix this specific leak without installing a full security suite. Developers hardening a custom site for a privacy-conscious client will also find it useful.

Who Should Skip It

If you already run a comprehensive security plugin like Wordfence, Really Simple Security, or All-In-One Security, you likely do not need this, since those tools cover REST API hardening and far more. Sites that rely on the user endpoints for legitimate frontend functionality, such as custom author pages populated via the REST API, should also avoid it.

The Bottom Line

SMNTCS Disable REST API User Endpoints is a tidy, focused fix for a specific REST API enumeration issue, but its overall quality score of 45.91/100 reflects real weaknesses in support depth, ratings volume, and long-term maintenance signals. Most WordPress site owners will be better served by a broader security plugin that includes this fix alongside firewall and login protection. Use it only if you specifically want a minimal, single-purpose tool and you accept the small-installer risk that comes with that choice.

Tags

privacy rest-api security user enumeration users