Title: Balada Fix
Author: vladanrs
Published: <strong>26.03.2026</strong>
Last modified: 26.03.2026

---

Поиск плагинов

![](https://ps.w.org/balada-fix/assets/icon-256x256.png?rev=3491702)

# Balada Fix

 Автор: [vladanrs](https://profiles.wordpress.org/vladanrs/)

[Скачать](https://downloads.wordpress.org/plugin/balada-fix.1.1.0.zip)

 * [Детали](https://ru.wordpress.org/plugins/balada-fix/#description)
 * [Отзывы](https://ru.wordpress.org/plugins/balada-fix/#reviews)
 *  [Установка](https://ru.wordpress.org/plugins/balada-fix/#installation)
 * [Разработка](https://ru.wordpress.org/plugins/balada-fix/#developers)

 [Поддержка](https://wordpress.org/support/plugin/balada-fix/)

## Описание

Balada Fix protects your site from unauthenticated abuse of specific WordPress REST
API endpoints. Such endpoints (for example the tagDiv theme’s `wp-json/tdw/save_css`)
are often targeted by the «Balada Injector» and similar campaigns to inject malicious
scripts.

 * Add one or more REST path patterns in **Settings  Balada Fix** (one per line).
 * Only logged-in administrators with the `edit_theme_options` capability can access
   those paths.
 * Unauthenticated or unauthorized requests receive a 403 Forbidden response.

Default protected path: `tdw/save_css` (tagDiv / Newspaper theme vulnerability).

## Скриншоты

 * [[
 * Screenshot installed plugin

## Установка

 1. Upload the plugin files to `/wp-content/plugins/balada-fix/`, or install through
    WordPress Plugins  Add New  Upload.
 2. Activate the plugin through the Plugins screen.
 3. Go to Settings  Balada Fix to review or add blocked paths (one per line, e.g. `
    wp-json/tdw/save_css` or `tdw/save_css`).

## Часто задаваемые вопросы

### Which paths should I add?

Add the REST path that is known to be vulnerable and should only be used by admins.
Example: `tdw/save_css` for the tagDiv Composer / Newspaper theme. You can use the
full path like `wp-json/tdw/save_css` or the short form `tdw/save_css`.

### Will this break my theme?

No. Legitimate use (when you are logged in as an administrator) continues to work.
Only unauthenticated or non-admin access to the listed paths is blocked.

## Отзывы

![](https://secure.gravatar.com/avatar/39818c0d4d0fcdb8b3915ef9a94e24d47d1d0b9cc0ddf54e7eb2bd38f211d1aa?
s=60&d=retro&r=g)

### 󠀁[Clean and easy](https://wordpress.org/support/topic/clean-and-easy-34/)󠁿

 [vladan92](https://profiles.wordpress.org/vladan92/) 26.03.2026

Works perfect!

 [ Посмотреть 1 отзыв ](https://wordpress.org/support/plugin/balada-fix/reviews/)

## Участники и разработчики

«Balada Fix» — проект с открытым исходным кодом. В развитие плагина внесли свой 
вклад следующие участники:

Участники

 *   [ vladanrs ](https://profiles.wordpress.org/vladanrs/)

[Перевести «Balada Fix» на ваш язык.](https://translate.wordpress.org/projects/wp-plugins/balada-fix)

### Заинтересованы в разработке?

[Посмотрите код](https://plugins.trac.wordpress.org/browser/balada-fix/), проверьте
[SVN репозиторий](https://plugins.svn.wordpress.org/balada-fix/), или подпишитесь
на [журнал разработки](https://plugins.trac.wordpress.org/log/balada-fix/) по [RSS](https://plugins.trac.wordpress.org/log/balada-fix/?limit=100&mode=stop_on_copy&format=rss).

## Журнал изменений

#### 1.1.0

 * Added Settings  Balada Fix page to configure blocked paths.
 * Support for multiple paths (one per line).
 * Default path: tdw/save_css.

#### 1.0.0

 * Initial release. Blocked unauthenticated access to tdw/save_css.

## Мета

 *  Версия **1.1.0**
 *  Обновление: **2 месяца назад**
 *  Активных установок: **10+**
 *  Версия WordPress ** 5.0 или выше **
 *  Совместим вплоть до: **6.9.4**
 *  Версия PHP ** 7.2 или выше **
 *  Язык
 * [English (US)](https://wordpress.org/plugins/balada-fix/)
 * Метки:
 * [injector](https://ru.wordpress.org/plugins/tags/injector/)[rest-api](https://ru.wordpress.org/plugins/tags/rest-api/)
   [security](https://ru.wordpress.org/plugins/tags/security/)[wp-json](https://ru.wordpress.org/plugins/tags/wp-json/)
 *  [Дополнительно](https://ru.wordpress.org/plugins/balada-fix/advanced/)

## Оценки

 5 из 5 звёзд.

 *  [  1 5-звездный отзыв     ](https://wordpress.org/support/plugin/balada-fix/reviews/?filter=5)
 *  [  0 4-звездный отзыв     ](https://wordpress.org/support/plugin/balada-fix/reviews/?filter=4)
 *  [  0 3-звездный отзыв     ](https://wordpress.org/support/plugin/balada-fix/reviews/?filter=3)
 *  [  0 2-звездный отзыв     ](https://wordpress.org/support/plugin/balada-fix/reviews/?filter=2)
 *  [  0 1-звездный отзыв     ](https://wordpress.org/support/plugin/balada-fix/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/balada-fix/reviews/#new-post)

[Посмотреть всеотзывы](https://wordpress.org/support/plugin/balada-fix/reviews/)

## Участники

 *   [ vladanrs ](https://profiles.wordpress.org/vladanrs/)

## Поддержка

Есть что сказать? Нужна помощь?

 [Перейти в форум поддержки](https://wordpress.org/support/plugin/balada-fix/)