Disable XML-RPC


Pretty simply, this plugin disables the XML-RPC API on a WordPress site running 3.5 or above.

Beginning in 3.5, XML-RPC is enabled by default. Additionally, the option to disable/enable XML-RPC was removed. For various reasons, site owners may wish to disable this functionality. This plugin provides an easy way to do so.


  1. Upload the disable-xml-rpc directory to the /wp-content/plugins/ directory in your WordPress installation
  2. Activate the plugin through the ‘Plugins’ menu in WordPress
  3. XML-RPC is now disabled!

To re-enable XML-RPC, just deactivate the plugin through the ‘Plugins’ menu.


Is there an admin interface for this plugin?

No. This plugin is as simple as XML-RPC is off (plugin activated) or XML-RPC is on (plugin is deactivated).

How do I know if the plugin is working?

There are two easy methods for checking if XML-RPC is off. First, try using an XML-RPC client, like the official WordPress mobile apps. Or you can try the XML-RPC Validator, written by Danilo Ercoli of the Automattic Mobile Team – the tool is available at http://xmlrpc.eritreo.it/ with a blog post about it at http://daniloercoli.com/2012/05/15/wordpress-xml-rpc-endpoint-validator/. Keep in mind that you want the validator to fail and tell you that XML-RPC services are disabled.


So great!

So great! Imagination and incredible! I have tried a number of measures, but I finally got this plugin found. 5 stars for this plugin. Many thanks.

Just works

I’ve been chasing around all morning to find out why my site was running like a dog. Looking into APC vs opcache and php-fpm options etc

Finally thought to look in the logs and saw constant xml-rpc post entries.

Installed this plugin and enabled it, and the site was instantly fixed.

Highly recommended, and enough to make me register and review!

Something that works at last – thank you!

After days of off and on brute force attempts on two of my clients sites, this plugin stopped them dead as soon as I activated it.
I have needed this plugin many times in the past, so glad I have installed it now. I will add it to all my client sites from now on.
Thank you developers.

Read all 15 reviews

Contributors & Developers

“Disable XML-RPC” is open source software. The following people have contributed to this plugin.




  • Blank lines removed from the plugin file.


  • Initial release