WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by Delower Hossain v1.4.0

Simple Disable XML-RPC

Simply disable XML-RPC on your WordPress site with a simple toggle switch. Protect your site from XML-RPC attacks and improve security.

Simple Disable XML-RPC

The facts

Rating
5★ from 5
Active installs
1k+
Price
Free
Last updated
9 Nov 2025
Added
Dec 2023
Requires WP
6.1
Tested up to
WP 6.8.8
Requires PHP
7.4
Downloads
9,729

Our analysis

AI-assisted

Simple Disable XML-RPC is a WordPress plugin designed to control XML-RPC functionality, enhancing your site's security against brute force and DDoS attacks. It allows you to disable XML-RPC with a single click, thereby reducing vulnerabilities associated with this protocol.

This plugin is suitable for security-focused website owners, particularly those who do not use mobile apps or remote publishing features. It is lightweight and aims to improve performance by reducing server load and resource usage.

Best for: Website owners prioritising security and performance who do not rely on XML-RPC features.

What it does well

  • One-click control to disable XML-RPC
  • Enhances security against XML-RPC attacks
  • Reduces server load and resource usage
  • Clean and modern admin interface
  • Translation ready and mobile responsive

Where it falls short

  • Disabling XML-RPC may affect certain features like mobile apps and Jetpack
  • Limited information on user experiences or additional features

Verdict

This plugin offers a straightforward solution for those looking to enhance WordPress security by disabling XML-RPC. It is particularly useful for users not dependent on related functionalities.

From the developer

Delower Hossain's own description of Simple Disable XML-RPC, lightly tidied.

Simple Disable XML-RPC is a lightweight, powerful WordPress plugin that gives you complete control over your site’s XML-RPC functionality. Protect your WordPress site from brute force attacks, DDoS attempts, and other XML-RPC security vulnerabilities with just one click.

🔒 Why Disable XML-RPC?

XML-RPC is a remote communication protocol that allows external applications to interact with your WordPress site. While useful for some services, it’s frequently exploited by attackers for:

  • Brute Force Attacks – Automated password guessing attempts
  • DDoS Attacks – Overwhelming your server with requests
  • Resource Exhaustion – Slowing down your website
  • Pingback Vulnerabilities – Exploiting pingback features

✨ Key Features

  • 🎯 One-Click Control – Modern toggle switch interface (NEW in v1.4.0)
  • 🔐 Enhanced Security – Block XML-RPC attacks instantly
  • ⚡ Improved Performance – Reduce server load and resource usage
  • 🎨 Beautiful Admin Interface – Clean, modern card-based design (NEW in v1.4.0)
  • 🌐 Translation Ready – Fully internationalized and translation-ready
  • 📱 Mobile Responsive – Settings page works perfectly on all devices
  • 🧹 Clean Uninstall – Removes all data when uninstalled
  • ⚙️ Developer Friendly – Well-coded, follows WordPress standards
  • 🔄 Regular Updates – Actively maintained and tested with latest WordPress versions
  • 💯 Lightweight – No bloat, minimal impact on your site

🆕 What’s New in Version 1.4.0

  • ✅ Modern toggle switch replaces old checkbox
  • ✅ Beautiful card-based admin interface
  • ✅ Enhanced security with proper sanitization
  • ✅ Better code organization (OOP approach)
  • ✅ Improved accessibility and UX
  • ✅ Removes X-Pingback header when disabled
  • ✅ Fixed activation redirect for bulk installations
  • ✅ Better mobile responsive design

🎯 Perfect For

  • Security-focused website owners
  • Sites that don’t use mobile apps or remote publishing
  • Sites experiencing XML-RPC attacks
  • Performance-conscious administrators
  • Anyone wanting better control over WordPress features

🔧 How It Works

This plugin uses the native WordPress xmlrpc_enabled filter to safely disable XML-RPC without modifying core files. Simply activate the plugin, toggle the switch on the settings page, and you’re protected!

⚠️ Important Note

Disabling XML-RPC may affect:
* WordPress mobile apps
* Jetpack (some features)
* Remote publishing tools
* Pingbacks and trackbacks
* Third-party services that rely on XML-RPC

Only disable XML-RPC if you don’t use these features.

🤝 Contributing & Bug Reports

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)