Sรฉbastien Dumont's Avatar

Sรฉbastien Dumont

@sebd86

๐Ÿ›’ Decouples @woocommerce.com with @cocartapi.bsky.socialโ€ฌ and secures API's with apisecurity.pro Lifetime offer available until 30th September https://linktr.ee/sebastiendumont

19
Followers
19
Following
15
Posts
25.09.2023
Joined
Posts Following

Latest posts by Sรฉbastien Dumont @sebd86

The #WordPress REST API is an open book. See the problem for yourself.

Try this on any site: add /wp-json/ to the end of the domain and see the long list of information publically available for hackersโ€”just ready to scrape data, spam requests, and poke for vulnerabilities. ๐Ÿ˜ฑ

31.08.2025 18:47 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

Each #WordPress REST API namespace provides it's own index. Leaving it open for hackers to have a directory to use to their advantage. Public access should be denied by default. ๐Ÿ˜จ

Get API Security and we will send them down a black hole instead.

apisecurity.pro

31.08.2025 18:47 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
API Security - Secure the WordPress REST API effortlessly Safe guard your REST API in seconds from unknown outsiders with enhanced security, limit requests and protect data exposure.

So what are you waiting for. Get API Security to secure your REST API today.

apisecurity.pro

31.08.2025 18:47 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

API Security protects you from all of that automatically, silently, while improving traffic control from outsiders and allowing the core of WordPressยฎ, your applications and your trusted tools to use it normally.

Giving you peace of mindโ€”without slowing your site down. ๐Ÿ™‚

31.08.2025 18:47 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

To make things worse, and sorry to be of bad news. The REST API is accesible on unsecure HTTP connections. ๐Ÿ’€

31.08.2025 18:47 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Wait theres more. Now imagine getting DDOS because you can't lockdown access to the REST API to prevent abuse from excessive calls. Now your suffering from performance degradation on the host running your site. Your current security plugin doesn't help. ๐Ÿ˜ 

31.08.2025 18:47 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Not scary enough for you. Now view the users endpoint /wp-json/wp/v2/users

See all those user ID's and usernames exposed including administrators. ๐Ÿคฎ

31.08.2025 18:47 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

The #WordPress REST API is an open book. See the problem for yourself.

Try this on any site: add /wp-json/ to the end of the domain and see the long list of information publically available for hackersโ€”just ready to scrape data, spam requests, and poke for vulnerabilities. ๐Ÿ˜ฑ

31.08.2025 18:47 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

If anyone uses the REST API in applications and would like to try it out and write a blog post on it so it gets more attention. Please DM to discuss.

31.08.2025 18:45 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
API Security - Secure the WordPress REST API effortlessly Safe guard your REST API in seconds from unknown outsiders with enhanced security, limit requests and protect data exposure.

Please visit apisecurity.pro to learn more and repost for others.

31.08.2025 18:45 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

With API Security, we provide that solution without hacking at the REST API. We cover everything those articles suggest and more without compromising how the core REST API functions and no configuration required. You can test out our security via a demo.

app.instawp.io/launch?t=api...

31.08.2025 18:45 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

I see so many articles about how to secure the #WordPress REST API and explain what you should do. They mostly copy each other providing the same code snippets to disable for unauthorized and remove endpoints if not logged in. None of them actually provide a real solution.

31.08.2025 18:45 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Hello everyone! - API Security Tired of leaving your WordPress REST API wide open? Hackers love unsecured APIs. They can scrape data, spam requests, and poke for vulnerabilities, or even manipulate content. We just launched API Sec...

Hey everyone!

I just launched API Securityโ€”a zero-config #WordPress plugin that instantly locks down your REST API, blocks unknown outsiders, limits abusive requests, and protects your data.

Details on LTD offer: apisecurity.pro/hello-everyo...

Request demo: app.instawp.io/launch?t=api...

18.08.2025 18:19 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

New #WordPress security plugin coming soon that addresses areas that have not been touched by other plugins out there.

29.01.2025 13:59 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
GitHub - co-cart/co-cart: ๐Ÿ›’ CoCart's developer-friendly REST API integrates with WooCommerce to decouple your storefront and convert it blazing-fast, build in any web framework. ๐Ÿ›’ CoCart's developer-friendly REST API integrates with WooCommerce to decouple your storefront and convert it blazing-fast, build in any web framework. - co-cart/co-cart

If you like to show some appreciation for the work I have done with just the core of my #WordPress plugin CoCart, you can now #sponsor it's development. Rewards are also available. Thank you in advance. ๐Ÿซถ

github.com/co-cart/co-c...

03.12.2024 20:52 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Hello world!

25.09.2023 11:57 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0