sandywp / plugins / simple-disable-xml-rpc

Simple Disable XML-RPC | Reduce Brute Force & DDOS Attacks

5.0 out of 5 stars. 5.0 5 reviews

Simply disable XML-RPC on your WordPress site with a simple toggle switch. Protect your site from XML-RPC attacks and improve security.

Launch a sandbox with this plugin → No signup.
Ready in seconds.

v1.4.0 1,000+ installs WP 6.1+ PHP 7.4+

your-sandbox.sandywp.com/wp-admin
Simple Disable XML-RPC | Reduce Brute Force & DDOS Attacks running inside a SandyWP sandbox

What you get inside

2 screens
  • Modern Settings Page - Beautiful card-based interface with toggle switch

  • Toggle Switch in Action - Easy one-click enable/disable control

About this plugin

Simple Disable XML-RPC is a lightweight, powerful WordPress plugin that gives you complete control over your site’s XML-RPC functionality. Protect your WordPress site from brute force attacks, DDoS attempts, and other XML-RPC security vulnerabilities with just one click.

🔒 Why Disable XML-RPC?

XML-RPC is a remote communication protocol that allows external applications to interact with your WordPress site. While useful for some services, it’s frequently exploited by attackers for:

  • Brute Force Attacks – Automated password guessing attempts
  • DDoS Attacks – Overwhelming your server with requests
  • Resource Exhaustion – Slowing down your website
  • Pingback Vulnerabilities – Exploiting pingback features

✨ Key Features

  • 🎯 One-Click Control – Modern toggle switch interface (NEW in v1.4.0)
  • 🔐 Enhanced Security – Block XML-RPC attacks instantly
  • ⚡ Improved Performance – Reduce server load and resource usage
  • 🎨 Beautiful Admin Interface – Clean, modern card-based design (NEW in v1.4.0)
  • 🌐 Translation Ready – Fully internationalized and translation-ready
  • 📱 Mobile Responsive – Settings page works perfectly on all devices
  • 🧹 Clean Uninstall – Removes all data when uninstalled
  • ⚙️ Developer Friendly – Well-coded, follows WordPress standards
  • 🔄 Regular Updates – Actively maintained and tested with latest WordPress versions
  • 💯 Lightweight – No bloat, minimal impact on your site

🆕 What’s New in Version 1.4.0

  • ✅ Modern toggle switch replaces old checkbox
  • ✅ Beautiful card-based admin interface
  • ✅ Enhanced security with proper sanitization
  • ✅ Better code organization (OOP approach)
  • ✅ Improved accessibility and UX
  • ✅ Removes X-Pingback header when disabled
  • ✅ Fixed activation redirect for bulk installations
  • ✅ Better mobile responsive design

🎯 Perfect For

  • Security-focused website owners
  • Sites that don’t use mobile apps or remote publishing
  • Sites experiencing XML-RPC attacks
  • Performance-conscious administrators
  • Anyone wanting better control over WordPress features

🔧 How It Works

This plugin uses the native WordPress xmlrpc_enabled filter to safely disable XML-RPC without modifying core files. Simply activate the plugin, toggle the switch on the settings page, and you’re protected!

⚠️ Important Note

Disabling XML-RPC may affect:
* WordPress mobile apps
* Jetpack (some features)
* Remote publishing tools
* Pingbacks and trackbacks
* Third-party services that rely on XML-RPC

Only disable XML-RPC if you don’t use these features.

🤝 Contributing & Bug Reports

Bug reports and pull requests are welcome on GitHub. Help us make this plugin better!

💝 Support the Development

If you find this plugin helpful, please consider:
* ⭐ Rating it 5 stars
* 🐛 Reporting bugs
* 💬 Suggesting features
* ☕ Buying us a coffee

Privacy Policy

Simple Disable XML-RPC does not:

  • Collect any user data
  • Store any personal information
  • Make external API calls
  • Use cookies or tracking
  • Send data to third parties

The plugin only stores one setting in your WordPress database: whether XML-RPC is enabled or disabled.

Support

Need help? We’re here for you!

Credits

Developed with ❤️ by WordPress Satkhira Community

Contributors:
* wpdelower
* monarchwp23

Special thanks to all our users and contributors who help make this plugin better!

Questions

What is XML-RPC and why should I disable it?

XML-RPC is a remote procedure call protocol that allows external applications to communicate with your WordPress site. While it enables features like mobile apps and remote publishing, it’s also a common target for:

  • Brute force attacks
  • DDoS attacks
  • Server resource exhaustion
  • Security vulnerabilities

If you don’t use WordPress mobile apps, Jetpack, or remote publishing tools, it’s recommended to disable XML-RPC for better security.

Will this plugin break my site?

No, this plugin safely disables XML-RPC using WordPress’s native filter. However, it may affect:

  • WordPress mobile apps
  • Jetpack functionality
  • Pingbacks and trackbacks
  • Third-party services using XML-RPC API

Test after activation to ensure your required features still work.

How do I know if XML-RPC is successfully disabled?

There are several ways to verify:

Method 1: WordPress Mobile App
Try connecting with the official WordPress mobile app. You should see: “XML-RPC services are disabled on this site”

Method 2: Online Validator
Use the XML-RPC Validator tool. When properly disabled, it will show an error message.

You should receive a response indicating XML-RPC is disabled.

Does this plugin improve website performance?

Yes! When XML-RPC is disabled, your server doesn’t need to process XML-RPC requests, which can:

  • Reduce server load
  • Prevent resource exhaustion
  • Speed up response times
  • Save bandwidth

Is this plugin compatible with other security plugins?

Yes! Simple Disable XML-RPC works seamlessly with other security plugins like:

  • Wordfence Security
  • Sucuri Security
  • iThemes Security
  • All In One WP Security
  • And more!

What’s the difference between disabling via .htaccess vs this plugin?

Plugin Method (Recommended):
* Uses WordPress native filters
* Easier to manage
* No server configuration needed
* Can be toggled on/off easily
* Won’t cause server errors

.htaccess Method:
* Requires manual file editing
* Can break if edited incorrectly
* Harder to reverse
* May cause conflicts

Can I re-enable XML-RPC if needed?

Absolutely! Just go to Settings > Disable XML-RPC and toggle the switch off. Changes take effect immediately.

Does this work on WordPress multisite?

Yes, the plugin works on both single WordPress installations and multisite networks. On multisite, it must be configured per-site.

5.0

5 reviews

  • 5 ★ 5
  • 4 ★ 0
  • 3 ★ 0
  • 2 ★ 0
  • 1 ★ 0

Ratings come from WordPress.org. SandyWP does not collect its own reviews.

Spin up a real WordPress site in seconds.

Test plugins, build a demo, hand a client a link — then squash it and start again. No local setup, no Docker.