Remove & Disable XML-RPC Pingback
Prevent pingback, XML-RPC and denial of service DDOS attacks by disabling the XML-RPC pingback functionality.
The facts
- Rating
- 3★ from 6
- Active installs
- 8k+
- Price
- Free
- Last updated
- 24 Jul 2023
- Added
- Mar 2014
- Requires WP
- 5.2
- Tested up to
- WP 6.3.10
- Requires PHP
- 5.6
- Downloads
- 95,902
Our analysis
AI-assistedRemove & Disable XML-RPC Pingback is a WordPress plugin designed to prevent your site from being exploited in pingback denial of service attacks. Once activated, it automatically disables XML-RPC without the need for any configuration.
This plugin is suitable for users who want to enhance their site's security against potential attacks while still allowing the use of other plugins that rely on XML-RPC functionality.
Best for: This plugin is best for WordPress site owners concerned about security and denial of service attacks.
What it does well
- ✓Automatically disables XML-RPC upon activation
- ✓Reduces server CPU usage
- ✓Prevents your site from being used in denial of service attacks
- ✓No configuration needed after activation
Where it falls short
- •Limited information on features and user experience
- •May conflict with plugins that require XML-RPC
Verdict
Remove & Disable XML-RPC Pingback offers a straightforward solution for improving site security, but its effectiveness may vary depending on your site's specific needs and plugin usage.
From the developer
cleverplugins's own description of Remove & Disable XML-RPC Pingback, lightly tidied.
Prevent your WordPress site from participating and being a victim of pingback denial of service attacks. After activation the plugin automatically disables XML-RPC. There’s no need to configure anything.
By disabling the XML-RPC pingback you’ll:
* lower your server CPU usage
* prevent malicious scripts from using your site to run pingback denial of service attacks
* prevent malicious scripts to run denial of service attacks on your site via pingback
From sucuri.net:
Any WordPress site with Pingback enabled (which is on by default) can be used in DDOS attacks against other sites.
Learn More
- How To Prevent WordPress From Participating In Pingback Denial of Service Attacks – wptavern.com
- More Than 162,000 WordPress Sites Used for Distributed Denial of Service Attack – sucuri.net
- xmlrpc.php and Pingbacks and Denial of Service Attacks, Oh My! – hackguard.com
Is Your Site Attacking Others?
Use Sucuri’s WordPress DDOS Scanner to check if your site is DDOS’ing other websites
Why Not Just Disable XMLRPC Altogether?
Yes, you can choose to do that, but if you use popular plugins like JetPack (that use XMLRPC) then those plugins will stop working. That is why this small plugin exists.