Remove XML-RPC Methods
View on WordPress.orgScores higher than 18% of indexed plugins
About
Remove all WordPress methods from the XML-RPC API to increase security.
What It Does
Remove XML-RPC Methods strips all WordPress methods from the XML-RPC API endpoint, effectively disabling XML-RPC functionality on your site. It mitigates brute-force amplification and pingback-based DDoS attacks by closing off a remote access vector many site owners no longer use. The plugin is intentionally narrow in scope and performs no other security functions.
Who It's For
This plugin fits security-hardened WordPress installations where the administrator has confirmed no reliance on XML-RPC for the WordPress mobile app, Jetpack, pingbacks, or third-party publishing tools. It is a good match for compliance-driven corporate intranets and private sites that need to demonstrate a hardened API surface. Developers and agencies who manage hardened WordPress deployments will appreciate its zero-bloat approach.
Who Should Skip It
Anyone using the WordPress mobile app, Jetpack, legacy blogging clients, or any third-party service that authenticates via xmlrpc.php should skip this plugin entirely, as it will break those integrations. Sites that already run a security suite like Wordfence or Really Simple Security with XML-RPC blocking enabled do not need this standalone tool.
The Bottom Line
Remove XML-RPC Methods scores 66.93/100 and does one thing competently with strong maintenance and compatibility signals. Its small install count and untested support channel keep the score modest, and its single-purpose nature makes it redundant for users of larger security plugins. A solid targeted pick, but only for admins who have fully audited their site for XML-RPC dependencies.
Related Plugins
Pick this if you want XML-RPC disabling bundled with a broader security hardening suite and far larger install base.
Pick this if you need a full firewall, malware scanning, and rule-based XML-RPC blocking in one package.
Pick this if you actively use Jetpack features, though note Jetpack itself relies on XML-RPC in many cases.
Pick this if you want XML-RPC locking as part of a wider free firewall and login hardening toolkit.
Listed in the security category but unrelated in scope; it sanitises SVG uploads rather than touching XML-RPC.