Disable XML-RPC Pingback
View on WordPress.orgScores higher than 26% of indexed plugins
About
Stops abuse of your site's XML-RPC by simply removing some methods used by attackers. While you can use the rest of XML-RPC methods.
What It Does
Disable XML-RPC Pingback removes the pingback and related XML-RPC methods that attackers commonly exploit for DDoS amplification, brute-force credential testing, and cross-site port scanning. Crucially, it leaves the rest of the XML-RPC surface intact, so apps like Jetpack and the WordPress mobile apps continue to function. Setup is a one-click activation with no settings page to configure.
Who It's For
This plugin is a good fit for site owners who have noticed suspicious traffic hitting xmlrpc.php or who want a targeted hardening step without disabling XML-RPC entirely. It is especially useful for blogs and small business sites that do not rely on pingbacks but still need XML-RPC for tools like Jetpack or remote publishing.
Who Should Skip It
If you already use a security plugin or WAF rule that blocks xmlrpc.php entirely (such as Cloudflare or a host-level firewall), this plugin is redundant. Sites that genuinely depend on pingbacks for legitimate inter-blog communication should also avoid it.
The Bottom Line
Disable XML-RPC Pingback does one specific job and does it well, with recent maintenance and broad compatibility that justify its 74.46 overall quality score. The lack of any support thread history is a soft warning sign, though the plugin is small enough that issues are unlikely. For sites that only need pingback protection without breaking Jetpack or mobile apps, it remains a sensible lightweight choice.
Related Plugins
Pick SiteGuard if you want broader login and admin protection alongside XML-RPC controls, not just pingback removal.
Not a direct competitor; only relevant if your XML-RPC concern is actually about import workflows rather than pingback abuse.
Choose this if your XML traffic concern is about sitemaps and search engine discovery rather than RPC exploits.
Choose Disable XML-RPC-API if you want to kill the entire XML-RPC endpoint rather than surgically remove pingback methods.
Pick Cloudflare if you would rather block malicious XML-RPC traffic at the edge instead of modifying WordPress behaviour at all.