{"id":380288,"date":"2026-10-05T16:40:18","date_gmt":"2026-10-05T16:40:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/fixora-disable-xml-rpc\/"},"modified":"2026-10-05T16:40:00","modified_gmt":"2026-10-05T16:40:00","slug":"fixora-disable-xml-rpc","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/fixora-disable-xml-rpc\/","author":18505484,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.1","stable_tag":"1.0.1","tested":"7.1.3","requires":"6.4","requires_php":"7.4","requires_plugins":null,"header_name":"Fixora Disable XML-RPC","header_author":"Fixora Labs","header_description":"Fixora disable xml-rpc and xmlrpc pingback with a blocked-attempt log\u2014see recent blocks in Settings.","assets_banners_color":"101b38","last_updated":"2026-10-05 16:40:00","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":212,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.1":{"tag":"1.0.1","author":"0322lf","date":"2026-10-05 16:40:00","revision":3729304}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3729303,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3729303,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3729303,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3729303,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3729303,"resolution":"1","location":"assets","locale":"","width":1280,"height":1013},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3729303,"resolution":"2","location":"assets","locale":"","width":850,"height":408},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3729303,"resolution":"3","location":"assets","locale":"","width":700,"height":172}},"screenshots":{"1":"Settings \u2192 Fixora Disable XML-RPC: choose the protection mode (Off, Disable XML-RPC entirely, or Block only pingback.ping), optionally allow Jetpack, and review the blocked-attempt log and status check on one screen.","2":"Blocked XML-RPC attempts log showing the time, remote IP address, and XML-RPC method of recent blocked requests (up to the last 50 entries).","3":"XML-RPC status check: the \"Check xmlrpc.php now\" button requests your site's xmlrpc.php and reports whether it appears blocked."}},"plugin_section":[],"plugin_tags":[42034,42035,3026,14731],"plugin_category":[44],"plugin_contributors":[282371],"plugin_business_model":[],"class_list":["post-380288","plugin","type-plugin","status-publish","hentry","plugin_tags-disable-xml-rpc","plugin_tags-disable-xmlrpc","plugin_tags-pingback","plugin_tags-xmlrpc","plugin_category-discussion-and-community","plugin_contributors-0322lf","plugin_committers-0322lf"],"banners":{"banner":"https:\/\/ps.w.org\/fixora-disable-xml-rpc\/assets\/banner-772x250.png?rev=3729303","banner_2x":"https:\/\/ps.w.org\/fixora-disable-xml-rpc\/assets\/banner-1544x500.png?rev=3729303","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/fixora-disable-xml-rpc\/assets\/icon-128x128.png?rev=3729303","icon_2x":"https:\/\/ps.w.org\/fixora-disable-xml-rpc\/assets\/icon-256x256.png?rev=3729303","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/fixora-disable-xml-rpc\/assets\/screenshot-1.png?rev=3729303","caption":"Settings \u2192 Fixora Disable XML-RPC: choose the protection mode (Off, Disable XML-RPC entirely, or Block only pingback.ping), optionally allow Jetpack, and review the blocked-attempt log and status check on one screen."},{"src":"https:\/\/ps.w.org\/fixora-disable-xml-rpc\/assets\/screenshot-2.png?rev=3729303","caption":"Blocked XML-RPC attempts log showing the time, remote IP address, and XML-RPC method of recent blocked requests (up to the last 50 entries)."},{"src":"https:\/\/ps.w.org\/fixora-disable-xml-rpc\/assets\/screenshot-3.png?rev=3729303","caption":"XML-RPC status check: the \"Check xmlrpc.php now\" button requests your site's xmlrpc.php and reports whether it appears blocked."}],"raw_content":"<!--section=description-->\n<p>Fixora Disable XML-RPC helps you disable xml-rpc, disable xmlrpc abuse, and reduce pingback exposure on your WordPress site.<\/p>\n\n<ul>\n<li><strong>Disable XML-RPC entirely<\/strong> \u2014 turns off XML-RPC and blocks direct access to <code>xmlrpc.php<\/code> (unless Jetpack is allowed).<\/li>\n<li><strong>Blocked-attempt log<\/strong> \u2014 records blocked XML-RPC requests (time, remote IP, and method name only). View the count and recent entries under <strong>Settings \u2192 Fixora Disable XML-RPC<\/strong>. Stores up to the last 50 entries in a single option.<\/li>\n<li><strong>Remove X-Pingback and pingback link discovery<\/strong> \u2014 when protection is active.<\/li>\n<li><strong>Pingback-only mode<\/strong> \u2014 blocks only <code>pingback.ping<\/code> while leaving other XML-RPC methods available.<\/li>\n<li><strong>Allow Jetpack<\/strong> \u2014 optional checkbox so Jetpack can keep using XML-RPC when the plugin is active.<\/li>\n<li><strong>Admin status check<\/strong> \u2014 requests <code>xmlrpc.php<\/code> from the settings screen and reports whether it appears blocked.<\/li>\n<\/ul>\n\n<p>This plugin does not provide firewall lists or additional hardening beyond the features above.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>fixora-disable-xml-rpc<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> screen. XML-RPC is disabled immediately (full block mode) without opening settings.<\/li>\n<li>Optional: go to <strong>Settings \u2192 Fixora Disable XML-RPC<\/strong> to switch to pingback-only, allow Jetpack, or turn protection off.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20break%20jetpack%3F\"><h3>Will this break Jetpack?<\/h3><\/dt>\n<dd><p>Enable <strong>Allow Jetpack<\/strong> on the settings page. When Jetpack is active, full XML-RPC blocking is skipped so Jetpack can continue to work.<\/p><\/dd>\n<dt id=\"what%20is%20pingback-only%20mode%3F\"><h3>What is pingback-only mode?<\/h3><\/dt>\n<dd><p>XML-RPC stays enabled, but <code>pingback.ping<\/code> is removed from the available methods. Pingback headers and discovery links are still removed.<\/p><\/dd>\n<dt id=\"what%20does%20the%20blocked-attempt%20log%20store%3F\"><h3>What does the blocked-attempt log store?<\/h3><\/dt>\n<dd><p>Only the time of the block, the remote IP address, and the XML-RPC method name when it can be read from the request. It does not store request bodies, headers, cookies, or credentials.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Add blocked-attempt log (time, IP, method) with a 50-entry cap on the settings screen.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Fixora disable xml-rpc and xmlrpc pingback with a blocked-attempt log\u2014see recent blocks in Settings.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/380288","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=380288"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/0322lf"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=380288"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=380288"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=380288"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=380288"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=380288"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=380288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}