=== Marketingbende Tiny Fix: Disable REST API User Endpoints ===
Contributors: marketingbende
Tags: rest-api, users, security
Requires at least: 5.0
Tested up to: 6.9
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Hides and blocks `/wp/v2/users` REST API endpoints for users who cannot list users.

== Description ==

Marketingbende Tiny Fix: Disable REST API User Endpoints is a small, single-purpose WordPress plugin. Activate it and the fix is applied immediately.

* Disable REST API User Endpoints: Hides and blocks `/wp/v2/users` REST API endpoints for users who cannot list users.

The free WordPress.org plugin is fully functional without a license key, account, payment, or external service.

== Optional Pro Add-on ==

An optional Pro add-on may be available separately outside WordPress.org for EUR 1 as a one-time lifetime unlock. It is not required for the free fix to work.

* Disable REST API User Endpoints: Standalone Pro package for Disable REST API User Endpoints: installs independently, includes the working fix, reports Pro status to the free plugin when present, and adds an admin control to pause the Pro fix without uninstalling.

Support, setup help, consulting, and custom compatibility work are not included.

== Installation ==

1. Upload this plugin folder to the /wp-content/plugins/ directory, or upload the ZIP through Plugins > Add New > Upload Plugin.
2. Activate the plugin through the Plugins screen.
3. Deactivate the plugin to revert its behavior.

== Risk Notes ==

* Disable REST API User Endpoints: Medium. Reduces public user enumeration; may affect front-end code that intentionally reads user data via REST.

== Changelog ==

= 1.0.0 =
* Initial generated version.
