Simple Disable XML-RPC | Reduce Brute Force & DDOS Attacks
View on WordPress.orgScores higher than 16% of indexed plugins
About
Simply disable XML-RPC on your WordPress site with a simple toggle switch. Protect your site from XML-RPC attacks and improve security.
What It Does
Simple Disable XML-RPC provides a single toggle switch in the WordPress admin that fully disables the XML-RPC endpoint (xmlrpc.php) on your site. This blocks remote publishing apps, pingbacks, trackbacks, and the brute force amplification attacks that frequently target xmlrpc.php. Once activated, the plugin closes the door on a protocol most modern WordPress installations no longer need.
Who It's For
This plugin is best for small site owners, bloggers, and lean-budget operators who want a zero-config, one-click lockdown against XML-RPC based attacks without learning server-side rules. It is particularly useful if your host has flagged xmlrpc.php traffic or your server is under brute force or DDoS pressure. Sites that do not use the WordPress mobile app, Jetpack, or third-party tools that require XML-RPC will benefit most.
Who Should Skip It
If you rely on the WordPress mobile app, Jetpack, or any third-party service that publishes content remotely via XML-RPC, do not install this plugin because it will break those integrations. Anyone already protected by a WAF or host-level firewall that blocks xmlrpc.php will see no benefit from adding another layer.
The Bottom Line
Simple Disable XML-RPC does exactly what it promises in one click, and its perfect rating from early users reflects that narrow but useful scope. The plugin is best treated as a tactical fix rather than a complete security strategy, and the zero support history means you are trusting a developer with no public track record. If you just need xmlrpc.php shut off and you do not use remote publishing tools, it is a fine choice; otherwise, the more widely installed Disable XML-RPC or Disable XML-RPC-API plugins are safer bets.
Related Plugins
Pick MalCare when you need full-stack security including malware scanning, firewall, and login protection, not just XML-RPC disablement.
Pick the original Disable XML-RPC plugin if you want the same one-click function with a longer install base of 200,000 and a more established track record.
Pick WP All Import only if your XML-RPC usage is tied to legitimate XML data imports, since it serves the opposite need of keeping xmlrpc.php functional.
Pick this sitemap plugin if you need XML output for search engines, which is unrelated to XML-RPC but commonly confused with it.
Pick Disable XML-RPC-API for similar single-purpose blocking with 100,000 installs and broader community validation behind it.