Gallop
by Gallop Software 1 (0 reviews)

Gallop

A REST API for headless Next.js sites: a page's post, SEO, and site data in one request, plus cookie login for authenticated front ends.

Gallop ranks #65,923 among WordPress.org plugins with 1+ active installations, is #1,020 of 1,589 in the Authentication category, a 1/5 rating from 0 reviews, and was last updated Jun 22, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7 (Current: 7.1.1)
v0.1.1 Current Version v0.1.1
Updated 2 months ago Last Update on 22 Jun, 2026
Refreshed 10 hours ago Last Refreshed on
#1,020 of 1,589 in Authentication
View on WordPress.org
Rank
#65,923
No change
Active Installs
1+
No change
KW Avg Position
60
No change
Downloads
165
+1 today
Support Resolved
0%
No change
Rating
20%
Review 1 out of 5
1 (0 reviews)

Next Milestone 10

Total Progress 10%
0+ 10+
65,221
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 9 more installs to reach 10+

Rank Changes

45,081 51,325 57,570 63,815 70,059 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
45,004 51,338 57,672 64,006 70,341 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
Current #65,923
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
0 10 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

1.0
0 reviews
Overall 20%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about Gallop

No. Gallop's REST endpoints are framework-agnostic JSON. Next.js is the reference target and the redirect feature is named for it, but any HTTP client can consume the API.
No. The redirect runs on template_redirect only, skips any request with a preview=true or _wp* query parameter, and never touches /wp-admin or /wp-json. Leave the Next.js URL setting blank to disable redirection entirely.
/gallop/v1/auth/login calls wp_signon() and sets the standard WordPress auth cookies. A Next.js front end on the same registered domain can then call /gallop/v1/auth/session (or any other authenticated REST endpoint) with credentials included. There is no JWT layer — cookie auth is intentional.
Yes. Five failed attempts per username + client IP within fifteen minutes return HTTP 429 until the window expires. Successful logins clear the counter.
By default Gallop uses REMOTE_ADDR for the per-IP portion of the login rate limit. If your site sits behind a trusted reverse proxy (Cloudflare, a load balancer, etc.) that overwrites the client-IP headers, enable Trust proxy IP headers on the Gallop settings screen so CF-Connecting-IP / X-Forwarded-For are used instead. Leave it off on direct-served sites — turning it on without a trusted proxy lets attackers spoof those headers to bypass the rate limit. The setting can also be overridden in code via the gallop_trust_forwarded_ip filter.
No. If Yoast is not active the seo field in responses is an empty object. With Yoast active, Gallop reads from its indexables to populate canonical, OpenGraph, and robots data.
No. Posts, pages, media, and built-in taxonomies are left alone. Only post types you create through the Gallop admin screen are registered by this plugin.
Deactivating stops Gallop from registering its post types and REST routes; content created under those post types stays in the database. Deleting the plugin (via the Plugins screen) additionally removes the gallop_post_types, gallop_nextjs_production_url, and gallop_trust_forwarded_ip options plus any leftover login rate-limit transients. Posts authored under your custom post types are intentionally left in place so they survive an uninstall/reinstall.

Sign In / Register

You need to sign in or register to use this feature.