sandywp / plugins / stop-xml-rpc-attacks
Stop XML-RPC Attacks
Blocks dangerous XML-RPC methods while preserving Jetpack, WooCommerce, and mobile apps compatibility.
Ready in seconds.
v2.0.0 6,000+ installs WP 6.0+ PHP 7.4+

About this plugin
Stop XML-RPC Attacks protects your WordPress site from XML-RPC brute force attacks, DDoS attempts, and reconnaissance probes while maintaining compatibility with essential services like Jetpack and WooCommerce.
Features:
- Three security modes: Full Disable, Guest Disable, or Selective Blocking
- Blocks dangerous methods: system.multicall, pingback.ping, and more
- Compatible with Jetpack and WooCommerce
- Optional user enumeration blocking
- Attack logging for monitoring
- Zero configuration required – works out of the box
- Clean, intuitive admin interface
Questions
- Will this break Jetpack?
No! The default “Selective Blocking” mode is fully compatible with Jetpack and WooCommerce.
- What’s the difference between the security modes?
- Full Disable: Maximum security, disables XML-RPC completely
- Guest Disable: Balanced approach, only allows XML-RPC for logged-in users
- Selective Blocking: Best compatibility, only blocks dangerous methods
- How do I enable logging?
Go to Settings > XML-RPC Security and check “Enable Attack Logging”. Logs will be written to your debug.log file when WP_DEBUG is enabled.
sandywp / also on the shelf
Try another plugin
Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force…
4.8 · 1M+ installs
WordPress login security with brute force protection, Two-factor authentication (2FA/MFA), firewall, IP/country blocking, and…
Anti-Malware Security and Brute-Force Firewall
4.9 · 100K+ installs
This Anti-Malware scanner searches for Malware, Viruses, and other security threats and vulnerabilities on your server and it…
5.0 · 100K+ installs
CloudSecure WP Securityは、管理画面とログインURLをサイバー攻撃から守る、国産・日本語対応のセキュリティ対策プラグインです。 簡単な設定だけで、不正アクセスや不正ログインからWordPressを保護し、サイトのセキュリティを高めます。
Spin up a real WordPress site in seconds.
Test plugins, build a demo, hand a client a link — then squash it and start again. No local setup, no Docker.