WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by cleverplugins v1.6

Remove & Disable XML-RPC Pingback

Prevent pingback, XML-RPC and denial of service DDOS attacks by disabling the XML-RPC pingback functionality.

Remove & Disable XML-RPC Pingback

The facts

Rating
3★ from 6
Active installs
8k+
Price
Free
Last updated
24 Jul 2023
Added
Mar 2014
Requires WP
5.2
Tested up to
WP 6.3.10
Requires PHP
5.6
Downloads
95,902

Our analysis

AI-assisted

Remove & Disable XML-RPC Pingback is a WordPress plugin designed to prevent your site from being exploited in pingback denial of service attacks. Once activated, it automatically disables XML-RPC without the need for any configuration.

This plugin is suitable for users who want to enhance their site's security against potential attacks while still allowing the use of other plugins that rely on XML-RPC functionality.

Best for: This plugin is best for WordPress site owners concerned about security and denial of service attacks.

What it does well

  • Automatically disables XML-RPC upon activation
  • Reduces server CPU usage
  • Prevents your site from being used in denial of service attacks
  • No configuration needed after activation

Where it falls short

  • Limited information on features and user experience
  • May conflict with plugins that require XML-RPC

Verdict

Remove & Disable XML-RPC Pingback offers a straightforward solution for improving site security, but its effectiveness may vary depending on your site's specific needs and plugin usage.

From the developer

cleverplugins's own description of Remove & Disable XML-RPC Pingback, lightly tidied.

Prevent your WordPress site from participating and being a victim of pingback denial of service attacks. After activation the plugin automatically disables XML-RPC. There’s no need to configure anything.

By disabling the XML-RPC pingback you’ll:
* lower your server CPU usage
* prevent malicious scripts from using your site to run pingback denial of service attacks
* prevent malicious scripts to run denial of service attacks on your site via pingback

From sucuri.net:

Any WordPress site with Pingback enabled (which is on by default) can be used in DDOS attacks against other sites.

Learn More

Is Your Site Attacking Others?

Use Sucuri’s WordPress DDOS Scanner to check if your site is DDOS’ing other websites

Why Not Just Disable XMLRPC Altogether?

Yes, you can choose to do that, but if you use popular plugins like JetPack (that use XMLRPC) then those plugins will stop working. That is why this small plugin exists.

Read the full description on the official page →

Tagged as