sandywp / plugins / stop-xml-rpc-attacks

Stop XML-RPC Attacks

5.0 out of 5 stars. 5.0 4 reviews

Blocks dangerous XML-RPC methods while preserving Jetpack, WooCommerce, and mobile apps compatibility.

Launch a sandbox with this plugin → No signup.
Ready in seconds.

v2.0.0 6,000+ installs WP 6.0+ PHP 7.4+

your-sandbox.sandywp.com/wp-admin
Stop XML-RPC Attacks running inside a SandyWP sandbox

About this plugin

Stop XML-RPC Attacks protects your WordPress site from XML-RPC brute force attacks, DDoS attempts, and reconnaissance probes while maintaining compatibility with essential services like Jetpack and WooCommerce.

Features:

  • Three security modes: Full Disable, Guest Disable, or Selective Blocking
  • Blocks dangerous methods: system.multicall, pingback.ping, and more
  • Compatible with Jetpack and WooCommerce
  • Optional user enumeration blocking
  • Attack logging for monitoring
  • Zero configuration required – works out of the box
  • Clean, intuitive admin interface

Questions

Will this break Jetpack?

No! The default “Selective Blocking” mode is fully compatible with Jetpack and WooCommerce.

What’s the difference between the security modes?

  • Full Disable: Maximum security, disables XML-RPC completely
  • Guest Disable: Balanced approach, only allows XML-RPC for logged-in users
  • Selective Blocking: Best compatibility, only blocks dangerous methods

How do I enable logging?

Go to Settings > XML-RPC Security and check “Enable Attack Logging”. Logs will be written to your debug.log file when WP_DEBUG is enabled.

5.0

4 reviews

  • 5 ★ 4
  • 4 ★ 0
  • 3 ★ 0
  • 2 ★ 0
  • 1 ★ 0

Ratings come from WordPress.org. SandyWP does not collect its own reviews.

sandywp / also on the shelf

Try another plugin

Spin up a real WordPress site in seconds.

Test plugins, build a demo, hand a client a link — then squash it and start again. No local setup, no Docker.