This plugin hasn’t been tested with the latest 3 major releases of WordPress. It may no longer be maintained or supported and may have compatibility issues when used with more recent versions of WordPress.



REST API introduced in WordPress 4.4 is a great resource for people interested in using it, but if you don’t want to use it probably you will want to close this new door to your WordPress.

Fortunately the WP core team provides hooks and filters to turn it off. This plugin simply makes use of them to disable the REST API server and remove its HTTP header and link tag.

SUPPORT: If you have any support question, please create an issue at the Github repository.


  • WordPress 4.4 or higher.


  • Extract the zip file and just drop the contents in the wp-content/plugins/ directory of your WordPress installation (or install it directly from your dashboard) and then activate the plugin from Plugins page.
  • There’s not options page, simply install and activate.


How can I test if the REST API was really disabled?

Just use your browser to go to (replace with your site domain). You will see the following message:

{"code":"rest_disabled","message":"The REST API is disabled on this site."}

You can also check your HTTP headers and your site page source code to see that the link to is gone.


works perfectly

Much easier than editing functions.php. This removed the "Link" HTTP header entirely. Perfect!

Simple to disable REST API

Thank you for this plug-in, glad I don't have to dig around in WordPress code to disable the API functionality. I don't use it and don't want another door for potential exploits.
Read all 3 reviews

Contributors & Developers

“SAR Disable REST API” is open source software. The following people have contributed to this plugin.


Translate “SAR Disable REST API” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.



  • Initial release