Simple Disable XML-RPC | Reduce Brute Force & DDOS Attacks
by Delower Hossain 5 (5 reviews)

Simple Disable XML-RPC | Reduce Brute Force & DDOS Attacks

Simply disable XML-RPC on your WordPress site with a simple toggle switch. Protect your site from XML-RPC attacks and improve security.

Simple Disable XML-RPC ranks #6,183 among WordPress.org plugins with 1,000+ active installations, is #366 of 4,482 in the Security category, a 5/5 rating from 5 reviews, and was last updated Nov 9, 2025. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 6.8 (Current: 7.1)
v1.4.0 Current Version v1.4.0
Updated 10 months ago Last Update on 09 Nov, 2025
Refreshed 11 hours ago Last Refreshed on
#366 of 4,482 in Security Top 10% by installs Downloads +7.5% this week
View on WordPress.org
Rank
#6,183
No change
Active Installs
1K+
-32.2%
KW Avg Position
47.2
No change
Downloads
8.7K
+11 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (5 reviews)

Next Milestone 2K

Total Progress 13%
1K+ 2K+
6,134
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 870 more installs to reach 2K+

Rank Changes

6,157 6,165 6,173 6,180 6,188 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
6,157 6,165 6,173 6,180 6,188 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Current #6,183
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 20 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
0 10 20 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
5 reviews
Overall 100%
5
5 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Support Threads Overview

Resolved
Unresolved
1
Total Threads
0
Resolved
1
Unresolved
0%
Resolution Rate

Security History

Source: WPVulnerability

No known vulnerabilities on record for Simple Disable XML-RPC. Checked 1 month ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners who want to disable XML-RPC to reduce security risks. It solves the problem of XML-RPC being exploited for brute force attacks, DDoS attempts, resource exhaustion, and pingback vulnerabilities.

  • One-click toggle switch
  • Removes X-Pingback header
  • Translation ready
  • Mobile responsive settings page
  • Clean uninstall removes data
  • Card-based admin interface
  • OOP code organization
  • No external API calls

Frequently Asked Questions

Common questions about Simple Disable XML-RPC | Reduce Brute Force & DDOS Attacks

XML-RPC is a remote procedure call protocol that allows external applications to communicate with your WordPress site. While it enables features like mobile apps and remote publishing, it's also a common target for: Brute force attacks DDoS attacks Server resource exhaustion Security vulnerabilities If you don't use WordPress mobile apps, Jetpack, or remote publishing tools, it's recommended to disable XML-RPC for better security.
No, this plugin safely disables XML-RPC using WordPress's native filter. However, it may affect: WordPress mobile apps Jetpack functionality Pingbacks and trackbacks Third-party services using XML-RPC API Test after activation to ensure your required features still work.
There are several ways to verify: Method 1: WordPress Mobile App Try connecting with the official WordPress mobile app. You should see: "XML-RPC services are disabled on this site" Method 2: Online Validator Use the XML-RPC Validator tool. When properly disabled, it will show an error message. You should receive a response indicating XML-RPC is disabled.
Yes! When XML-RPC is disabled, your server doesn't need to process XML-RPC requests, which can: Reduce server load Prevent resource exhaustion Speed up response times Save bandwidth
Yes! Simple Disable XML-RPC works seamlessly with other security plugins like: Wordfence Security Sucuri Security iThemes Security All In One WP Security And more!
Plugin Method (Recommended): * Uses WordPress native filters * Easier to manage * No server configuration needed * Can be toggled on/off easily * Won't cause server errors .htaccess Method: * Requires manual file editing * Can break if edited incorrectly * Harder to reverse * May cause conflicts
Absolutely! Just go to Settings > Disable XML-RPC and toggle the switch off. Changes take effect immediately.
Yes, the plugin works on both single WordPress installations and multisite networks. On multisite, it must be configured per-site.
Yes! We actively maintain this plugin and test it with every new WordPress release. Updates are pushed regularly to ensure compatibility and security.
WordPress.org Support Forum GitHub Issues Plugin Documentation

Sign In / Register

You need to sign in or register to use this feature.