Title: Fixora Disable XML-RPC
Author: Fixora Labs
Published: <strong>October 5, 2026</strong>
Last modified: October 5, 2026

---

Search plugins

![](https://ps.w.org/fixora-disable-xml-rpc/assets/banner-772x250.png?rev=3729303)

![](https://ps.w.org/fixora-disable-xml-rpc/assets/icon-256x256.png?rev=3729303)

# Fixora Disable XML-RPC

 By [Fixora Labs](https://profiles.wordpress.org/0322lf/)

[Download](https://downloads.wordpress.org/plugin/fixora-disable-xml-rpc.1.0.1.zip)

 * [Details](https://wordpress.org/plugins/fixora-disable-xml-rpc/#description)
 * [Reviews](https://wordpress.org/plugins/fixora-disable-xml-rpc/#reviews)
 *  [Installation](https://wordpress.org/plugins/fixora-disable-xml-rpc/#installation)
 * [Development](https://wordpress.org/plugins/fixora-disable-xml-rpc/#developers)

 [Support](https://wordpress.org/support/plugin/fixora-disable-xml-rpc/)

## Description

Fixora Disable XML-RPC helps you disable xml-rpc, disable xmlrpc abuse, and reduce
pingback exposure on your WordPress site.

 * **Disable XML-RPC entirely** — turns off XML-RPC and blocks direct access to `
   xmlrpc.php` (unless Jetpack is allowed).
 * **Blocked-attempt log** — records blocked XML-RPC requests (time, remote IP, 
   and method name only). View the count and recent entries under **Settings  Fixora
   Disable XML-RPC**. Stores up to the last 50 entries in a single option.
 * **Remove X-Pingback and pingback link discovery** — when protection is active.
 * **Pingback-only mode** — blocks only `pingback.ping` while leaving other XML-
   RPC methods available.
 * **Allow Jetpack** — optional checkbox so Jetpack can keep using XML-RPC when 
   the plugin is active.
 * **Admin status check** — requests `xmlrpc.php` from the settings screen and reports
   whether it appears blocked.

This plugin does not provide firewall lists or additional hardening beyond the features
above.

## Screenshots

[⌊Settings → Fixora Disable XML-RPC: choose the protection mode (Off, Disable XML-
RPC entirely, or Block only pingback.ping), optionally allow Jetpack, and review
the blocked-attempt log and status check on one screen.⌉⌊Settings → Fixora Disable
XML-RPC: choose the protection mode (Off, Disable XML-RPC entirely, or Block only
pingback.ping), optionally allow Jetpack, and review the blocked-attempt log and
status check on one screen.⌉[

Settings  Fixora Disable XML-RPC: choose the protection mode (Off, Disable XML-RPC
entirely, or Block only pingback.ping), optionally allow Jetpack, and review the
blocked-attempt log and status check on one screen.

[⌊Blocked XML-RPC attempts log showing the time, remote IP address, and XML-RPC 
method of recent blocked requests (up to the last 50 entries).⌉⌊Blocked XML-RPC 
attempts log showing the time, remote IP address, and XML-RPC method of recent blocked
requests (up to the last 50 entries).⌉[

Blocked XML-RPC attempts log showing the time, remote IP address, and XML-RPC method
of recent blocked requests (up to the last 50 entries).

[⌊XML-RPC status check: the "Check xmlrpc.php now" button requests your site's xmlrpc.
php and reports whether it appears blocked.⌉⌊XML-RPC status check: the "Check xmlrpc.
php now" button requests your site's xmlrpc.php and reports whether it appears blocked
.⌉[

XML-RPC status check: the “Check xmlrpc.php now” button requests your site’s xmlrpc.
php and reports whether it appears blocked.

## Installation

 1. Upload the `fixora-disable-xml-rpc` folder to `/wp-content/plugins/`.
 2. Activate the plugin through the **Plugins** screen. XML-RPC is disabled immediately(
    full block mode) without opening settings.
 3. Optional: go to **Settings  Fixora Disable XML-RPC** to switch to pingback-only,
    allow Jetpack, or turn protection off.

## FAQ

### Will this break Jetpack?

Enable **Allow Jetpack** on the settings page. When Jetpack is active, full XML-
RPC blocking is skipped so Jetpack can continue to work.

### What is pingback-only mode?

XML-RPC stays enabled, but `pingback.ping` is removed from the available methods.
Pingback headers and discovery links are still removed.

### What does the blocked-attempt log store?

Only the time of the block, the remote IP address, and the XML-RPC method name when
it can be read from the request. It does not store request bodies, headers, cookies,
or credentials.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Fixora Disable XML-RPC” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ Fixora Labs ](https://profiles.wordpress.org/0322lf/)

[Translate “Fixora Disable XML-RPC” into your language.](https://translate.wordpress.org/projects/wp-plugins/fixora-disable-xml-rpc)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/fixora-disable-xml-rpc/),
check out the [SVN repository](https://plugins.svn.wordpress.org/fixora-disable-xml-rpc/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/fixora-disable-xml-rpc/)
by [RSS](https://plugins.trac.wordpress.org/log/fixora-disable-xml-rpc/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.1

 * Add blocked-attempt log (time, IP, method) with a 50-entry cap on the settings
   screen.

#### 1.0.0

 * Initial release.

## Meta

 *  Version **1.0.1**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.4 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [disable xml-rpc](https://wordpress.org/plugins/tags/disable-xml-rpc/)[disable xmlrpc](https://wordpress.org/plugins/tags/disable-xmlrpc/)
   [pingback](https://wordpress.org/plugins/tags/pingback/)[xmlrpc](https://wordpress.org/plugins/tags/xmlrpc/)
 *  [Advanced View](https://wordpress.org/plugins/fixora-disable-xml-rpc/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/fixora-disable-xml-rpc/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/fixora-disable-xml-rpc/reviews/)

## Contributors

 *   [ Fixora Labs ](https://profiles.wordpress.org/0322lf/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/fixora-disable-xml-rpc/)