Disable XML-RPC-API icon

Disable XML-RPC-API

by Amin Nazemi

View on WordPress.org
80 Quality Score
Active Installs
23/30

With 100,000 active installs, the plugin has solid reach in its niche, though it trails the leading alternative by a factor of five.

Update Freshness
23/25

It was last updated on 2026-02-04 and is tested against WordPress 6.9.4, indicating the developer is actively keeping pace with core releases.

User Rating
13/15

A score of 84 from 43 reviewers is a positive signal, but the small sample size means individual experiences can swing the average.

Support Health
8/15

Zero support threads and a 0.0 percent resolution rate suggest either near-flawless operation or, more likely, that users have nowhere to turn if something breaks.

WP Compatibility
15/15

Full marks for compatibility: it requires only WordPress 5.0, declares no PHP version constraint, and has been tested on the latest 6.9.4 release.

Scores higher than 79% of indexed plugins

About

A simple and lightweight plugin to disable XML-RPC API, X-Pingback and pingback-ping in WordPress 3.5+ for a faster and more secure website

Active Installs 100k+
Rating ★★★★ 4.2/5
Last Updated 2026-02-04 6:54am GMT
Requires WordPress 5.0+
Tested Up To 6.9.7
✓ No known vulnerabilities

What It Does

Disable XML-RPC-API shuts down the XML-RPC endpoint on WordPress 3.5+ sites, blocking pingbacks and X-Pingback headers that are commonly abused for DDoS reflection and brute force amplification. In practice it adds a few filters to drop XML-RPC requests before they hit the application layer, which reduces server load and closes off a legacy attack surface. It does not affect the REST API or the admin dashboard.

Who It's For

This plugin suits site owners who do not use the WordPress mobile app, Jetpack, or third-party tools that rely on XML-RPC for remote publishing. It is a good fit for small business sites, blogs, and corporate intranets that have noticed brute force attempts targeting xmlrpc.php in their logs. Agencies hardening multiple client sites will also appreciate the zero-configuration approach.

Who Should Skip It

If you publish remotely using the WordPress mobile app, a desktop client like MarsEdit, or services such as IFTTT that require XML-RPC, installing this will break those workflows. You should also skip it if you already run a web application firewall or security plugin that disables XML-RPC, since stacking these tools adds no real benefit.

The Bottom Line

Disable XML-RPC-API is a competent, actively maintained plugin that does one job well and has earned a solid 82.49 quality score. Its main drawback is the absence of any visible support channel, so users troubleshooting a conflict are largely on their own. For most sites that do not depend on XML-RPC, it is a sensible, low-risk addition to a hardening checklist.

Tags

disable xml-rpc disable xmlrpc pingback stop brute force attacks xmlrpc