Stop XML-RPC Attacks
View on WordPress.orgScores higher than 52% of indexed plugins
About
Blocks dangerous XML-RPC methods while preserving Jetpack, WooCommerce, and mobile apps compatibility.
What It Does
Stop XML-RPC Attacks selectively blocks the XML-RPC methods most commonly abused by brute force and DDoS attacks, such as system.multicall and pingback.ping. It keeps approved endpoints functional so Jetpack syncing, WooCommerce mobile checkout, and official WordPress apps continue to work without interruption.
Who It's For
This plugin suits WordPress site owners who want targeted XML-RPC protection without disabling the protocol entirely, especially WooCommerce stores relying on mobile app access and publishers running Jetpack analytics. Agencies managing multiple client sites will appreciate the set-and-forget approach that avoids breaking legitimate integrations.
Who Should Skip It
Anyone already running a full security suite like Wordfence, Solid Security, or Jetpack's own brute force protection does not need this plugin, since those tools already filter XML-RPC traffic at the firewall level. Hobbyists on low-traffic personal blogs with no Jetpack or WooCommerce dependency can simply disable XML-RPC via a one-line function or .htaccess rule.
The Bottom Line
Stop XML-RPC Attacks does one specific job and does it with surgical precision, earning a 76.42 overall score driven by immaculate maintenance and compatibility marks. It is a sensible choice for sites that depend on Jetpack or WooCommerce but want to shut down brute force entry points, though the 6,000 install count and zero-thread support history make it harder to recommend over Wordfence or AIOS for users who want a full security stack. Treat it as a focused supplement rather than a replacement for a broader security strategy.
Related Plugins
Pick this if you want a full-stack security and SSL hardening solution that goes well beyond XML-RPC, with a 3 million install track record and broader feature coverage.
Pick this when you need an enterprise-grade firewall, malware scanner, and login throttling from a vendor with 5 million installs and a dedicated threat intelligence feed.
Pick this if you are already invested in the Jetpack ecosystem and want XML-RPC protection, brute force blocking, backups, and performance in one bundle.
Pick this for a free, modular security toolkit with granular firewall rules, login lockdown, and 1 million installs of community validation behind it.
Pick this when your primary security concern is sanitizing SVG uploads to prevent XSS, not XML-RPC abuse, as it addresses a completely different attack surface.