Remove XML-RPC Methods icon

Remove XML-RPC Methods

by Walter Ebert

View on WordPress.org
67 Quality Score
Active Installs
14/30

About 1,000 active installs places it in a niche, specialised category rather than a mainstream audience.

Update Freshness
25/25

A 2026-03-26 update and 7.0 compatibility testing reflect very recent and active maintenance.

User Rating
6/15

Two perfect ratings is encouraging but the sample size is too small to be statistically meaningful.

Support Health
8/15

Zero support threads means either no users have encountered issues or there is no visible support channel activity.

WP Compatibility
15/15

Tested up to WordPress 7.0 with PHP 5.4.0 minimum and no reported conflicts, earning full marks for compatibility.

Scores higher than 18% of indexed plugins

About

Remove all WordPress methods from the XML-RPC API to increase security.

Active Installs 1k+
Rating ★★★★★ 5/5
Last Updated 2026-08-18 6:03pm GMT
Requires WordPress 4.6+
Tested Up To 7.1
Requires PHP 5.4.0+
✓ No known vulnerabilities

What It Does

Remove XML-RPC Methods strips all WordPress methods from the XML-RPC API endpoint, effectively disabling XML-RPC functionality on your site. It mitigates brute-force amplification and pingback-based DDoS attacks by closing off a remote access vector many site owners no longer use. The plugin is intentionally narrow in scope and performs no other security functions.

Who It's For

This plugin fits security-hardened WordPress installations where the administrator has confirmed no reliance on XML-RPC for the WordPress mobile app, Jetpack, pingbacks, or third-party publishing tools. It is a good match for compliance-driven corporate intranets and private sites that need to demonstrate a hardened API surface. Developers and agencies who manage hardened WordPress deployments will appreciate its zero-bloat approach.

Who Should Skip It

Anyone using the WordPress mobile app, Jetpack, legacy blogging clients, or any third-party service that authenticates via xmlrpc.php should skip this plugin entirely, as it will break those integrations. Sites that already run a security suite like Wordfence or Really Simple Security with XML-RPC blocking enabled do not need this standalone tool.

The Bottom Line

Remove XML-RPC Methods scores 66.93/100 and does one thing competently with strong maintenance and compatibility signals. Its small install count and untested support channel keep the score modest, and its single-purpose nature makes it redundant for users of larger security plugins. A solid targeted pick, but only for admins who have fully audited their site for XML-RPC dependencies.

Tags

security xml-rpc xmlrpc