Disable XML-RPC Pingback icon

Disable XML-RPC Pingback

by Samuel Aguilera

View on WordPress.org
71 Quality Score
Active Installs
21/30

With roughly 60,000 active installs the plugin is well known in the security hardening niche, though it sits far behind multi-purpose alternatives like SiteGuard.

Update Freshness
19/25

Last updated on 2025-11-24 and tested against WordPress 6.8.5, the plugin is clearly being maintained against current core releases.

User Rating
12/15

A 78 out of 100 from 14 raters is decent but the very small sample size means the score should be read with some caution.

Support Health
8/15

Zero support threads opened and zero resolved means there is no track record of author responsiveness, which is worrying given how thin the plugin's footprint is.

WP Compatibility
11/15

Requiring WordPress 4.8 and PHP 5.6 makes it compatible with virtually every still-running WordPress install.

Scores higher than 26% of indexed plugins

About

Stops abuse of your site's XML-RPC by simply removing some methods used by attackers. While you can use the rest of XML-RPC methods.

Active Installs 60k+
Rating ★★★½ 3.9/5
Last Updated 2025-11-24 11:09am GMT
Requires WordPress 4.8+
Tested Up To 6.8.8
Requires PHP 5.6+
✓ No known vulnerabilities

What It Does

Disable XML-RPC Pingback removes the pingback and related XML-RPC methods that attackers commonly exploit for DDoS amplification, brute-force credential testing, and cross-site port scanning. Crucially, it leaves the rest of the XML-RPC surface intact, so apps like Jetpack and the WordPress mobile apps continue to function. Setup is a one-click activation with no settings page to configure.

Who It's For

This plugin is a good fit for site owners who have noticed suspicious traffic hitting xmlrpc.php or who want a targeted hardening step without disabling XML-RPC entirely. It is especially useful for blogs and small business sites that do not rely on pingbacks but still need XML-RPC for tools like Jetpack or remote publishing.

Who Should Skip It

If you already use a security plugin or WAF rule that blocks xmlrpc.php entirely (such as Cloudflare or a host-level firewall), this plugin is redundant. Sites that genuinely depend on pingbacks for legitimate inter-blog communication should also avoid it.

The Bottom Line

Disable XML-RPC Pingback does one specific job and does it well, with recent maintenance and broad compatibility that justify its 74.46 overall quality score. The lack of any support thread history is a soft warning sign, though the plugin is small enough that issues are unlikely. For sites that only need pingback protection without breaking Jetpack or mobile apps, it remains a sensible lightweight choice.

Tags

ddos pingback rpc xml xml-rpc