WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by Amin Nazemi v2.1.7

Disable XML-RPC-API

A simple and lightweight plugin to disable XML-RPC API, X-Pingback and pingback-ping in WordPress 3.5+ for a faster and more secure website

Disable XML-RPC-API

The facts

Rating
4.2★ from 43
Active installs
100k+
Price
Free
Last updated
4 Feb 2026
Added
Oct 2020
Requires WP
5.0
Tested up to
WP 6.9.7
Downloads
822,819

Our analysis

AI-assisted

Disable XML-RPC-API is a WordPress plugin designed to enhance website security by disabling the XML-RPC functionality. It protects against brute-force attacks and Denial of Service (DoS) attacks by restricting access to xmlrpc.php and managing trackbacks and pingbacks. This plugin is suitable for site owners who want to reduce vulnerabilities associated with XML-RPC.

Best for: This plugin is best for WordPress site owners concerned about security vulnerabilities related to XML-RPC.

What it does well

  • Disables XML-RPC to prevent brute-force attacks
  • Offers options to manage trackbacks and pingbacks
  • Allows IP whitelisting and blacklisting for XML-RPC
  • Includes features to speed up WordPress performance
  • Free to use from the WordPress.org directory

Where it falls short

  • Limited information on specific performance improvements
  • No details on user support or documentation

Verdict

Disable XML-RPC-API provides a straightforward solution for enhancing WordPress security. It is particularly useful for those looking to mitigate specific threats associated with XML-RPC functionality.

From the developer

Amin Nazemi's own description of Disable XML-RPC-API, lightly tidied.

Protect your website from xmlrpc brute-force attacks,DOS and DDOS attacks, this plugin disables the XML-RPC and trackbacks-pingbacks on your WordPress website.

PLUGIN FEATURES
(These are options you can enable or disable each one)

  • Disable access to xmlrpc.php file using .httacess file
  • Automatically change htaccess file permission to read-only (0444)
  • Disable X-pingback to minimize CPU usage
  • Disable selected methods from XML-RPC
  • Remove pingback-ping link from header
  • Disable trackbacks and pingbacks to avoid spammers and hackers
  • Rename XML-RPC slug to whatever you want
  • Black list IPs for XML-RPC
  • White list IPs for XML-RPC
  • Some options to speed-up your wordpress website
  • Disable JSON REST API
  • Hide WordPress Version
  • Disable built-in WordPress file editor
  • Disable wlw manifest
  • And some other options

What is XMLRPC

XML-RPC, or XML Remote Procedure Call is a protocol which uses XML to encode its calls and HTTP as a transport mechanism.
Beginning in WordPress 3.5, XML-RPC is enabled by default. Additionally, the option to disable/enable XML-RPC was removed. For various reasons, site owners may wish to disable this functionality. This plugin provides an easy way to do so.

Why you should disable XML-RPC
Xmlrpc has two main weaknesses

  • Brute force attacks:
    Attackers try to login to WordPress using xmlrpc.php with as many username/password combinations as they can enter. A method within xmlrpc.php allows the attacker to use a single command (system.multicall) to guess hundreds of passwords. Daniel Cid at Sucuri described it well in October 2015: “With only 3 or 4 HTTP requests, the attackers could try thousands of passwords, bypassing security tools that are designed to look and block brute force attempts.”
  • Denial of Service Attacks via Pingback:
    Back in 2013, attackers sent Pingback requests through xmlrpc.php of approximately 2500 WordPress sites to “herd (these sites) into a voluntary botnet,” according to Gur Schatz at Incapsula. “This gives any attacker a virtually limitless set of IP addresses to Distribute a Denial of Service attack across a network of over 100 million WordPress sites, without having to compromise them.”

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)