Stop XML-RPC Attacks icon

Stop XML-RPC Attacks

by Pascal CESCATO

View on WordPress.org
76 Quality Score
Active Installs
17/30

A modest 6,000 active installs signals niche adoption rather than mainstream recognition, but the score is boosted by steady, targeted demand from security-conscious operators.

Update Freshness
25/25

Updated as recently as May 2026 and tested against WordPress 7.0, the plugin shows exceptional maintenance discipline relative to its install base.

User Rating
12/15

Four perfect ratings is encouraging but statistically thin, so the 80/15 score reflects strong sentiment tempered by a very small sample size.

Support Health
8/15

Zero support threads and zero resolutions means there is no evidence either way of how the author handles real user problems.

WP Compatibility
15/15

Tested on WordPress 7.0 with a PHP 7.4 floor and clear allowance for Jetpack, WooCommerce, and mobile app traffic, the compatibility profile is excellent.

Scores higher than 52% of indexed plugins

About

Blocks dangerous XML-RPC methods while preserving Jetpack, WooCommerce, and mobile apps compatibility.

Active Installs 6k+
Rating ★★★★★ 5/5
Last Updated 2026-08-27 11:15pm GMT
Requires WordPress 6.0+
Tested Up To 7.1
Requires PHP 7.4+
✓ No known vulnerabilities

What It Does

Stop XML-RPC Attacks selectively blocks the XML-RPC methods most commonly abused by brute force and DDoS attacks, such as system.multicall and pingback.ping. It keeps approved endpoints functional so Jetpack syncing, WooCommerce mobile checkout, and official WordPress apps continue to work without interruption.

Who It's For

This plugin suits WordPress site owners who want targeted XML-RPC protection without disabling the protocol entirely, especially WooCommerce stores relying on mobile app access and publishers running Jetpack analytics. Agencies managing multiple client sites will appreciate the set-and-forget approach that avoids breaking legitimate integrations.

Who Should Skip It

Anyone already running a full security suite like Wordfence, Solid Security, or Jetpack's own brute force protection does not need this plugin, since those tools already filter XML-RPC traffic at the firewall level. Hobbyists on low-traffic personal blogs with no Jetpack or WooCommerce dependency can simply disable XML-RPC via a one-line function or .htaccess rule.

The Bottom Line

Stop XML-RPC Attacks does one specific job and does it with surgical precision, earning a 76.42 overall score driven by immaculate maintenance and compatibility marks. It is a sensible choice for sites that depend on Jetpack or WooCommerce but want to shut down brute force entry points, though the 6,000 install count and zero-thread support history make it harder to recommend over Wordfence or AIOS for users who want a full security stack. Treat it as a focused supplement rather than a replacement for a broader security strategy.

Tags

Brute Force ddos jetpack security xmlrpc