Disable then delete. I’d also check the .htaccess files after doing this to make sure they have defaulted back to their original state. If not then get a copy of the originals either from your backups or just download the latest WordPress and copy the htaccess file over.
Although in saying this, unless it’s causing any major problems I wouldn’t be disabling it. It’s a fine security plugin it just needs more thought put into settings.
For instance I have found 99% of the time when you enable the “No directory browsing” feature on an Apache server you WILL crash the site and get error 500 for every page.
There’s lots of little nuances like that, regardless it’s a great security plugin.