Disable XML-RPC Pingback
Stops abuse of your site's XML-RPC by simply removing some methods used by attackers. While you can use the rest of XML-RPC methods.
The facts
- Rating
- 3.9★ from 14
- Active installs
- 60k+
- Price
- Free
- Last updated
- 24 Nov 2025
- Added
- Mar 2014
- Requires WP
- 4.8
- Tested up to
- WP 6.8.8
- Requires PHP
- 5.6
- Downloads
- 429,666
Our analysis
AI-assistedDisable XML-RPC Pingback is a WordPress plugin designed to enhance the security of your site by removing specific XML-RPC methods that are often targeted by attackers. This allows you to retain the functionality of other XML-RPC methods needed by certain plugins and applications, such as mobile apps and Jetpack modules.
The plugin is suitable for users who want to protect their WordPress site from abuse while still utilising necessary XML-RPC features. It has been maintained since 2014 and complies with WordPress coding standards.
Best for: This plugin is best for WordPress site owners looking to enhance security without losing XML-RPC functionality.
What it does well
- ✓Removes specific XML-RPC methods used by attackers
- ✓Maintained since 2014
- ✓Compliant with WordPress coding standards
- ✓Retains necessary XML-RPC functionality for plugins
- ✓Free to use from the WordPress.org directory
Where it falls short
- •Limited feature information provided
- •Does not disable XML-RPC entirely
Verdict
Disable XML-RPC Pingback offers a straightforward solution for improving site security while maintaining essential features. It is a practical choice for those concerned about XML-RPC abuse.
From the developer
Samuel Aguilera's own description of Disable XML-RPC Pingback, lightly tidied.
Stops abuse of your site’s XML-RPC by simply removing some methods used by attackers. While you can use the rest of XML-RPC methods.
This is more friendly than disabling totally XML-RPC, that it’s needed by some plugins and apps (I.e. Mobile apps or some Jetpack’s modules).
- The original one.
- Simple and effective.
- No marketing buzz.
- Maintained and updated when needed since 2014.
- 100% compliant with WordPress coding standards which makes it fail safe.
- 60,000+ active installations can’t be wrong.
If you’re happy with the plugin please don’t forget to give it a good rating, it will motivate me to keep sharing and improving this plugin (and others).
Features
Removes the following methods from XML-RPC interface.
- pingback.ping
- pingback.extensions.getPingbacks
- X-Pingback from HTTP headers. This will hopefully stops some bots from trying to hit your xmlrpc.php file.
Requirements
- WordPress 3.8.1 or higher.