WordFence
In case you’re using WordFence plugin on sites you’re going to crosspost to, you need to keep in mind that you have to configure it properly.
In order to do so please visit WordFence > All Options, scroll down to the “Brute Force Protection” section. Here you need to make sure that checkboxes “Prevent discovery of usernames through ‘/?author=N’ scans, the oEmbed API, the WordPress REST API, and WordPress XML Sitemaps” and “Disable WordPress application passwords” are unchecked.

Ok, but what happens if you don’t do that?
- If you leave “Disable WordPress application passwords” checkbox checked then you can not create an application password in order to add a site in the plugin settings.
- If you leave “Prevent discovery of usernames through…” checkbox checked then when you try to crosspost a post to a site with WordFence active it will just fail silently (it doesn’t affect crossposting WooCommerce products though). WordFence doesn’t even care to return any kind of error message in this case so I can process it in my plugin and show you a notice that your WordFence is not configured or something.
In case, you are using Wordfence Premium, you may probably need to whitelist IP addresses here:
