Fixora Disable XML-RPC

Description

Fixora Disable XML-RPC helps you disable xml-rpc, disable xmlrpc abuse, and reduce pingback exposure on your WordPress site.

  • Disable XML-RPC entirely — turns off XML-RPC and blocks direct access to xmlrpc.php (unless Jetpack is allowed).
  • Blocked-attempt log — records blocked XML-RPC requests (time, remote IP, and method name only). View the count and recent entries under Settings Fixora Disable XML-RPC. Stores up to the last 50 entries in a single option.
  • Remove X-Pingback and pingback link discovery — when protection is active.
  • Pingback-only mode — blocks only pingback.ping while leaving other XML-RPC methods available.
  • Allow Jetpack — optional checkbox so Jetpack can keep using XML-RPC when the plugin is active.
  • Admin status check — requests xmlrpc.php from the settings screen and reports whether it appears blocked.

This plugin does not provide firewall lists or additional hardening beyond the features above.

Screenshots

Installation

  1. Upload the fixora-disable-xml-rpc folder to /wp-content/plugins/.
  2. Activate the plugin through the Plugins screen. XML-RPC is disabled immediately (full block mode) without opening settings.
  3. Optional: go to Settings Fixora Disable XML-RPC to switch to pingback-only, allow Jetpack, or turn protection off.

FAQ

Will this break Jetpack?

Enable Allow Jetpack on the settings page. When Jetpack is active, full XML-RPC blocking is skipped so Jetpack can continue to work.

What is pingback-only mode?

XML-RPC stays enabled, but pingback.ping is removed from the available methods. Pingback headers and discovery links are still removed.

What does the blocked-attempt log store?

Only the time of the block, the remote IP address, and the XML-RPC method name when it can be read from the request. It does not store request bodies, headers, cookies, or credentials.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Fixora Disable XML-RPC” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.0.1

  • Add blocked-attempt log (time, IP, method) with a 50-entry cap on the settings screen.

1.0.0

  • Initial release.