Simple Disable XML-RPC | Reduce Brute Force & DDOS Attacks icon

Simple Disable XML-RPC | Reduce Brute Force & DDOS Attacks

by Delower Hossain

View on WordPress.org
66 Quality Score
Active Installs
14/30

With only 1,000 active installs, this is a niche plugin, though it punched above its weight to earn the maximum user rating score.

Update Freshness
19/25

The plugin was updated on 2025-11-09 and is tested against WordPress 6.8.5, signalling an actively maintained codebase despite the solo developer footprint.

User Rating
15/15

A perfect 100/100 rating from 5 reviewers is encouraging, though the small sample size means this should be treated as anecdotal rather than statistically reliable.

Support Health
8/15

Zero support threads and zero resolutions is a real concern: there is no public track record showing the author responds to user issues, even if no one has needed help yet.

WP Compatibility
11/15

Tested with WordPress 6.8.5 and requiring PHP 7.4+, the plugin supports a modern but not bleeding-edge stack, which fits its narrow functional scope.

Scores higher than 16% of indexed plugins

About

Simply disable XML-RPC on your WordPress site with a simple toggle switch. Protect your site from XML-RPC attacks and improve security.

Active Installs 1k+
Rating ★★★★★ 5/5
Last Updated 2025-11-09 2:27am GMT
Requires WordPress 6.1+
Tested Up To 6.8.8
Requires PHP 7.4+
✓ No known vulnerabilities

What It Does

Simple Disable XML-RPC provides a single toggle switch in the WordPress admin that fully disables the XML-RPC endpoint (xmlrpc.php) on your site. This blocks remote publishing apps, pingbacks, trackbacks, and the brute force amplification attacks that frequently target xmlrpc.php. Once activated, the plugin closes the door on a protocol most modern WordPress installations no longer need.

Who It's For

This plugin is best for small site owners, bloggers, and lean-budget operators who want a zero-config, one-click lockdown against XML-RPC based attacks without learning server-side rules. It is particularly useful if your host has flagged xmlrpc.php traffic or your server is under brute force or DDoS pressure. Sites that do not use the WordPress mobile app, Jetpack, or third-party tools that require XML-RPC will benefit most.

Who Should Skip It

If you rely on the WordPress mobile app, Jetpack, or any third-party service that publishes content remotely via XML-RPC, do not install this plugin because it will break those integrations. Anyone already protected by a WAF or host-level firewall that blocks xmlrpc.php will see no benefit from adding another layer.

The Bottom Line

Simple Disable XML-RPC does exactly what it promises in one click, and its perfect rating from early users reflects that narrow but useful scope. The plugin is best treated as a tactical fix rather than a complete security strategy, and the zero support history means you are trusting a developer with no public track record. If you just need xmlrpc.php shut off and you do not use remote publishing tools, it is a fine choice; otherwise, the more widely installed Disable XML-RPC or Disable XML-RPC-API plugins are safer bets.

Tags

disable xml disable xml-rpc wordpress security xml xmlrpc