A
by
teamredfox
0 (0 reviews)
API Write Blocker
A plugin to control the operation of admin-ajax.php, REST API, and xmlrpc.
API Write Blocker ranks #37,855 among WordPress.org plugins with 10+ active installations, and was last updated Oct 27, 2025. Data from WordPress.org, refreshed twice daily — see methodology.
Tested up to WP 6.8.10 (Current: 7.1.2)
v1.0
Current Version v1.0
Updated 10 months ago
Last Update on 27 Oct, 2025
Refreshed 16 hours ago
Last Refreshed on
Top 50% by installs
Rank
#37,855
—
No change
Active Installs
10+
-16.7%
KW Avg Position
N/A
—
No change
Downloads
358
+1 today
Support Resolved
0%
—
No change
Rating
0%
Review 0 out of 5
0
(0 reviews)
Next Milestone 20
10+
20+
24,593
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro
Unlock Exact Install Count
See the precise estimated active installs for this plugin, calculated from real-time ranking data.
- Exact install estimates within tiers
- Track install growth over time
- Milestone progress predictions
Need 8 more installs to reach 20+
Rank Changes
Current
#37,855
Change
Best
#
Downloads Growth
Downloads
Growth
Peak
Upgrade to Pro
Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.
Upgrade NowReviews & Ratings
0.0
0 reviews
Overall
0%
5
0
(0%)
4
0
(0%)
3
0
(0%)
2
0
(0%)
1
0
(0%)
Track This Plugin
Get detailed analytics, keyword tracking, and position alerts delivered to your inbox.
Start Tracking FreePlugin Details
- Version
- 1.0
- Last Updated
- Oct 27, 2025
- Requires WP
- 6.8+
- Tested Up To
- 6.8.10
- PHP Version
- 7.4 or higher
- Author
- teamredfox
Support & Rating
- Rating
- ☆ ☆ ☆ ☆ ☆ 0
- Reviews
- 0
- Support Threads
- 0
- Resolved
- 0%
Frequently Asked Questions
Common questions about API Write Blocker
No, as long as you whitelist the required routes (e.g., contact-form-7/v1/contact-forms) and Ajax actions (e.g., wpcf7-submit). The plugin is designed to safely allow necessary requests.
Yes. Many sites do not use REST-based write operations publicly. By default, WordPress allows unauthenticated POST, PUT, and DELETE calls which may be exploited by attackers. This plugin disables them unless explicitly allowed.
Yes. This plugin blocks only post-related XML-RPC methods and lets other functions like pingbacks or basic metaWeblog info pass, if desired.
Authenticated (logged-in) users are always allowed to execute requests. This plugin mainly protects against unauthorized, anonymous, or non-whitelisted users.