Description
Fixora Disable XML-RPC helps you disable xml-rpc, disable xmlrpc abuse, and reduce pingback exposure on your WordPress site.
- Disable XML-RPC entirely — turns off XML-RPC and blocks direct access to
xmlrpc.php(unless Jetpack is allowed). - Blocked-attempt log — records blocked XML-RPC requests (time, remote IP, and method name only). View the count and recent entries under Settings Fixora Disable XML-RPC. Stores up to the last 50 entries in a single option.
- Remove X-Pingback and pingback link discovery — when protection is active.
- Pingback-only mode — blocks only
pingback.pingwhile leaving other XML-RPC methods available. - Allow Jetpack — optional checkbox so Jetpack can keep using XML-RPC when the plugin is active.
- Admin status check — requests
xmlrpc.phpfrom the settings screen and reports whether it appears blocked.
This plugin does not provide firewall lists or additional hardening beyond the features above.
Screenshots



Installation
- Upload the
fixora-disable-xml-rpcfolder to/wp-content/plugins/. - Activate the plugin through the Plugins screen. XML-RPC is disabled immediately (full block mode) without opening settings.
- Optional: go to Settings Fixora Disable XML-RPC to switch to pingback-only, allow Jetpack, or turn protection off.
FAQ
-
Will this break Jetpack?
-
Enable Allow Jetpack on the settings page. When Jetpack is active, full XML-RPC blocking is skipped so Jetpack can continue to work.
-
What is pingback-only mode?
-
XML-RPC stays enabled, but
pingback.pingis removed from the available methods. Pingback headers and discovery links are still removed. -
What does the blocked-attempt log store?
-
Only the time of the block, the remote IP address, and the XML-RPC method name when it can be read from the request. It does not store request bodies, headers, cookies, or credentials.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Fixora Disable XML-RPC” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Fixora Disable XML-RPC” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.1
- Add blocked-attempt log (time, IP, method) with a 50-entry cap on the settings screen.
1.0.0
- Initial release.
