Skip to main content
Agency Program Get 2× more leads and save 50% on hosting. Built for agencies ready to grow. Book a call
Disable XML-RPC-API icon

Disable XML-RPC-API

v2.1.7
by Amin Nazemi · 4.2 (40 reviews)

A simple and lightweight plugin to disable XML-RPC API, X-Pingback and pingback-ping in WordPress 3.5+ for a faster and more secure website

100K+ active installs Updated Dec 13, 2024 Tested to 6.7.2
Try Demo Download
Pre-installed Ready in ~10s No card
Disable XML-RPC-API

About Disable XML-RPC-API

This plugin protects your WordPress website from xmlrpc brute-force attacks, DOS and DDOS attacks by disabling the XML-RPC and trackbacks-pingbacks. It also has additional features such as disabling access to xmlrpc.php file, changing htaccess file permission, disabling X-pingback, and more. Disabling XML-RPC is important as it prevents brute force attacks and denial of service attacks via pingback.

Screenshots

Disable XML-RPC-API screenshot
Disable XML-RPC-API screenshot

Frequently asked questions

What is XML-RPC?
XML-RPC, or XML Remote Procedure Call, is a protocol that uses XML to encode its calls and HTTP as a transport mechanism. It has been enabled by default in WordPress since version 3.5, and the option to disable or enable it was removed. This plugin provides an easy way to disable this functionality.
Why should I disable XML-RPC?
XML-RPC has two main weaknesses: brute force attacks and Denial of Service (DoS) attacks via Pingback. Attackers can use xmlrpc.php to try many username/password combinations with a single command, bypassing security tools. Pingback functionality can also be exploited for DoS attacks.
What are some key features of this plugin?
This plugin allows you to disable access to the xmlrpc.php file, automatically change the .htaccess file permission to read-only, disable X-pingback to minimize CPU usage, and remove the pingback-ping link from the header. It also offers options to disable selected methods from XML-RPC, rename the XML-RPC slug, and blacklist or whitelist IPs for XML-RPC. Additionally, it can disable the JSON REST API, hide the WordPress Version, and disable the built-in WordPress file editor.

Changelog

1.0.0

  • Initial release

1.0.1

  • Fix bugs

1.0.5

  • Remove pingback link tag in header
  • Add ability to fix htaccess file permission

1.0.6

  • Fix warnings for htaccess permission

1.0.7

  • Fix blank page when using W3 Total Cache and some other cache plugins

1.0.8

  • Fix code conflict with Autoptimize plugin

1.0.9

  • WordPress 5.7 compatible
  • Fix some issues

2.0.0

  • Fix code conflict with some other plugin
  • Fix hiding data in WooCommerce Product Tabs

2.1.0

*Major Update
*Add “XML-RPC Security”settings menu
*Add some new features
*Fix plugin deactivation bug

2.1.1

  • Add new feature fix hotlinks
  • Change notif timing

2.1.2

  • Add an option to disable auto change htaccess permission
  • Fix “DISALLOW_FILE_EDIT” warning
  • WordPress 5.8 compatibility

2.1.3

  • Fix compatibility issue with WordPress 5.9
  • Fix htaccess cleaning function

2.1.4

  • Fix some minor bugs
  • Refactor the entire codes
  • Add a fallback function for situations htaccess is not working

2.1.4.2

  • Hotfix for error on update

2.1.4.3

  • Hotfix for error on removing v metadata

2.1.4.4

  • Fix warning undefined variable $htaccess_code when disable hotlink fix is off
  • Fix warning Undefined array key “plugins” on PHP 8+

2.1.4.5

  • Fix removing vpingback header issue in the last major update
  • Update tested up to wp 6.1

2.1.4.7

  • Fix issues on vuninstallation hook
  • Minor improvements on admin review notification

2.1.4.8

  • Fix bug v wp reset API option

2.1.4.9

  • Update Jetpack default whitelist IPs
  • Fix bug with update actions function
  • Keep enabling WP RSS in default settings
  • Test with WordPress 6.3 and update tested up to

2.1.5

  • Hotfix for .htaccess error and disabling the admin notices

2.1.6

  • Clean Up the plugin codes (remove unnecessary codes)
  • Add VaultPress IPs to JetPack allowlist
  • Test compatibility with WordPress 6.6.1

2.1.7

  • Improve disable xmlrpc fallback method
  • Test compatibility with WordPress 6.7.1

Try other plugins