Q: Hide My WP Ghost vs WPAutoBlog: AppSumo Contradiction
TIER 6 customer here.
WP-JSON Hacking Real Facts:
Sources: https://www.google.com/search?q=wp-json+hacking
APPSUMO CONTRADICTION:
AppSumo sold Hide My WP Ghost to protect wp-json: "wp-json is a path known by hackers and they will try to brute force it in order to obtain data or to break into your website."
Sources: https://hidemywpghost.com/hide-my-wp-ghost-security-features/
https://appsumo.com/products/hide-my-wp-ghost/
INCONSISTENCY:
AppSumo validates Hide My WP Ghost for wp-json protection
WPAutoBlog forces clients to expose those same endpoints
Your site https://wpautoblog.com/wp-json/wp/v2/posts/ returns 404
REQUEST: Add "Custom wp-json URL" field for AppSumo clients using Hide My WP Ghost.
AppSumo respects client security. Please help us use both AppSumo products together securely.
Timeline for implementation?
Hendrik_WPAutoBlog
Sep 11, 2025A: Hi,
we don't use WordPress for our website. If the REST API would be unsafe the WordPress development team wouldn't have added it. You can request them to remove it here: https://make.wordpress.org/core/reports/
You can also just turn it on for a day, synchronize 100 articles and then turn it off again. You can have them synchronized as draft and schedule them within Wordpress for release.