Disable XML-RPC icon

Disable XML-RPC

by Phil Erb

View on WordPress.org
84 Quality Score
Active Installs
24/30

With 200,000 active installs, this is by far the most widely adopted XML-RPC disabler in the WordPress ecosystem, which gives strong evidence of real-world trust.

Update Freshness
25/25

A 100 out of 100 maintenance score combined with a last update timestamp in May 2026 and compatibility tested against WordPress 7.0 indicates the author is actively keeping pace with core releases.

User Rating
13/15

A user rating of 86 out of 100 from 31 reviews is solid and consistent with the plugin doing one thing reliably without bloat.

Support Health
8/15

Support health sits at 50 out of 100 because there are zero resolved threads, which is unsurprising given the plugin's trivial scope but still worth noting.

WP Compatibility
15/15

Full marks for compatibility reflect its low minimum requirements, compatibility with WordPress 7.0, and a long-standing track record of working across the 3.5+ range.

Scores higher than 93% of indexed plugins

About

Disables the XML-RPC API in WordPress 3.5+, which is enabled by default.

Active Installs 200k+
Rating ★★★★ 4.2/5
Last Updated 2026-05-27 11:12pm GMT
Requires WordPress 3.5+
Tested Up To 7.0.4
✓ No known vulnerabilities

What It Does

Disable XML-RPC disables the XML-RPC API endpoint in WordPress 3.5+, which is enabled by default in core. In practical terms, it blocks remote publishing clients and apps that rely on XML-RPC from communicating with your site, closing a common attack surface used for brute force amplification and pingback-based DDoS abuse. The plugin does this with a single toggle and no configuration screens.

Who It's For

This plugin fits security-focused site owners running standard WordPress blogs, brochures, or small business sites that have no need for the legacy XML-RPC interface. It is also a reasonable hardening step for compliance-driven organizations looking to reduce their externally exposed API footprint with minimal effort.

Who Should Skip It

If you publish remotely through the WordPress mobile app, Jetpack, IFTTT, or any classic blogging client, do not install this plugin since it will break those integrations entirely. Sites relying on WooCommerce or BuddyPress components that use XML-RPC for legitimate requests should also avoid a blanket disable.

The Bottom Line

Disable XML-RPC is a focused, well-maintained plugin that does exactly one job and does it well, which is why it leads its category by a wide margin. The lack of support threads is a non-issue here because the plugin is essentially a single-flag switch, but anyone dependent on XML-RPC should stay clear. Overall Quality Score of 84.14 out of 100 makes it an easy recommendation for hardening sites that do not need the XML-RPC endpoint.

Tags

xmlrpc