Features
Everything you need for
professional-grade WordPress® API security
Just a few clicks away to put your mind at ease.


Top Feature
Removed Directory
Hiding sensitive details from the API index of your WordPress® site should be a high priority.
Don’t give hackers a direct roadmap on what can be used.
See for yourself: Access your API index now and see everything that your WordPress® site is currently exposing. It’s a lot.

I don’t need to worry about my WordPress REST API directory exposing everything anymore. 😍
— Mandi Alpine, Brandwich
Firewall
Block Unknown Agents
Deny access to any route used from unknown agents including bots at the door. Pre-vetted agents are only allowed in. No kung fu needed.
FYI: Most all API requests don’t specify a User Agent. This is because the device / browser passes this info automatically. However, this is not validated – allowing bots to also make requests.

This security plugin has been a pain. 💢
— Agent Smith, Bot


What’s your name?
Protect User Data
Anonymous user data. Prevent hackers getting a head start with listed usernames, ID’s exposed and more.
FYI: The users endpoint in WordPress® is an open book to the public for no specific reason. Just be glad emails are not shared there too.
Traffic
Rate Limiting
We automatically prevent abuse from excessive calls and performance degradation on the host running your site.
We allow you to take control to configure the time and limits per seconds to your requirements.


No access
Firewall
Getting attacked is not fun. We automatically lockdown access to the API with our comprehensive IP blacklisting system if we detect it’s being violated before it gets too bad.
Feel free to blacklist IP addresses manually if needed.

Identification
Unknown Caller
WordPress® is always passing along who you are when making any HTTP calls.
Hide the version you have installed and your site URL from being shared for extra security.
They don’t need it−so why give it!
Security
Always Secure
You never have to worry about posting data over an unsecure connection again.
Accept requests only on a secure connection. All your none-secure requests are redirected over a secure connection.


Ready for you
CoCart Compatible
100% ready for your headless store.
FYI: Some security measures are already available in CoCart, but that leaves the rest of your WordPress® site vulnerable.