WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by DeveloperWil v1.0.4

Deactivate XML-RPC Service

Disables the XMP-RPC API service introduced in WordPress 3.5 and above.

Deactivate XML-RPC Service

The facts

Active installs
100+
Price
Free
Last updated
23 Aug 2026
Added
Sep 2017
Requires WP
5.6
Tested up to
WP 7.1
Requires PHP
5.6
Downloads
4,384

Our analysis

AI-assisted

Deactivate XML-RPC Service is a WordPress plugin that disables the XML-RPC API, which allows remote clients to post, upload, and edit content. This plugin is suitable for users who do not require the XML-RPC functionality and want to enhance the security of their WordPress site by preventing remote access.

It is important to note that if you use the WordPress smartphone app or the Jetpack plugin, you will need to keep this service enabled, as both rely on XML-RPC to function properly. Additionally, other plugins and services that utilise the XML-RPC API may also be affected by this plugin's activation.

Best for: This plugin suits users who want to disable remote access to their WordPress site for security reasons.

What it does well

  • Completely disables the XML-RPC API
  • Enhances site security by preventing remote access
  • Free to use from the WordPress.org directory
  • Compatible with WordPress versions 3.5 and above
  • Active installation count of 100

Where it falls short

  • Disables functionality for the WordPress smartphone app and Jetpack plugin
  • May affect other plugins and services that rely on XML-RPC
  • Limited information on user ratings and feedback

Verdict

Deactivate XML-RPC Service is a straightforward solution for disabling XML-RPC, but it may not be suitable for users who rely on certain applications and services that require this functionality.

From the developer

DeveloperWil's own description of Deactivate XML-RPC Service, lightly tidied.

Completely disables the XML-RPC API which was introduced in WordPress 3.5 and above which lets remote clients post, upload and edit content.

Notes:
If you are using the WordPress smart phone app or the Jetpack plugin, please note that they need this service enabled.

If you activate this plugin your WordPress phone app will not be able to connect to your site and Jetpack will not be able to connect to wordpress.com where site visitor data (and other stuff) is stored.

Other plugins and services that use the XML-RPC API will also not function properly.

Plugin Page

Deactivate XML-RPC

Read the full description on the official page →

Tagged as