Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Simply disable XML-RPC on your WordPress site with a simple toggle switch. Protect your site from XML-RPC attacks and improve security.
Simple Disable XML-RPC is a WordPress plugin designed to control XML-RPC functionality, enhancing your site's security against brute force and DDoS attacks. It allows you to disable XML-RPC with a single click, thereby reducing vulnerabilities associated with this protocol.
This plugin is suitable for security-focused website owners, particularly those who do not use mobile apps or remote publishing features. It is lightweight and aims to improve performance by reducing server load and resource usage.
Best for: Website owners prioritising security and performance who do not rely on XML-RPC features.
What it does well
Where it falls short
This plugin offers a straightforward solution for those looking to enhance WordPress security by disabling XML-RPC. It is particularly useful for users not dependent on related functionalities.
Delower Hossain's own description of Simple Disable XML-RPC, lightly tidied.
Simple Disable XML-RPC is a lightweight, powerful WordPress plugin that gives you complete control over your site’s XML-RPC functionality. Protect your WordPress site from brute force attacks, DDoS attempts, and other XML-RPC security vulnerabilities with just one click.
XML-RPC is a remote communication protocol that allows external applications to interact with your WordPress site. While useful for some services, it’s frequently exploited by attackers for:
This plugin uses the native WordPress xmlrpc_enabled filter to safely disable XML-RPC without modifying core files. Simply activate the plugin, toggle the switch on the settings page, and you’re protected!
Disabling XML-RPC may affect:
* WordPress mobile apps
* Jetpack (some features)
* Remote publishing tools
* Pingbacks and trackbacks
* Third-party services that rely on XML-RPC
Only disable XML-RPC if you don’t use these features.
Other plugins for securing a site.
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...