Description
At a glance
Disable XML-RPC-API v2.1.7 — free WordPress plugin download. Key facts: 100K+ active installs · 4.2/5 rating from 43 reviews · updated February 4, 2026 · requires WordPress 5.0+.
Protect your website from xmlrpc brute-force attacks,DOS and DDOS attacks, this plugin disables the XML-RPC and trackbacks-pingbacks on your WordPress website.
PLUGIN FEATURES
(These are options you can enable or disable each one)
- Disable access to xmlrpc.php file using .httacess file
- Automatically change htaccess file permission to read-only (0444)
- Disable X-pingback to minimize CPU usage
- Disable selected methods from XML-RPC
- Remove pingback-ping link from header
- Disable trackbacks and pingbacks to avoid spammers and hackers
- Rename XML-RPC slug to whatever you want
- Black list IPs for XML-RPC
- White list IPs for XML-RPC
- Some options to speed-up your wordpress website
- Disable JSON REST API
- Hide WordPress Version
- Disable built-in WordPress file editor
- Disable wlw manifest
- And some other options
What is XMLRPC
XML-RPC, or XML Remote Procedure Call is a protocol which uses XML to encode its calls and HTTP as a transport mechanism.
Beginning in WordPress 3.5, XML-RPC is enabled by default. Additionally, the option to disable/enable XML-RPC was removed. For various reasons, site owners may wish to disable this functionality. This plugin provides an easy way to do so.
Why you should disable XML-RPC
Xmlrpc has two main weaknesses
- Brute force attacks:
Attackers try to login to WordPress using xmlrpc.php with as many username/password combinations as they can enter. A method within xmlrpc.php allows the attacker to use a single command (system.multicall) to guess hundreds of passwords. Daniel Cid at Sucuri described it well in October 2015: “With only 3 or 4 HTTP requests, the attackers could try thousands of passwords, bypassing security tools that are designed to look and block brute force attempts.” - Denial of Service Attacks via Pingback:
Back in 2013, attackers sent Pingback requests through xmlrpc.php of approximately 2500 WordPress sites to “herd (these sites) into a voluntary botnet,” according to Gur Schatz at Incapsula. “This gives any attacker a virtually limitless set of IP addresses to Distribute a Denial of Service attack across a network of over 100 million WordPress sites, without having to compromise them.”
Frequently asked questions
What do I get when I download Disable XML-RPC-API?
Disable XML-RPC-API 2.1.7 is the latest version. It is a WordPress plugin you can download here free of charge under the GPL license, with the complete feature set included and no trial limitations. It holds a 4.2/5 rating from 43 user reviews.
Does Disable XML-RPC-API cost anything?
No. Disable XML-RPC-API 2.1.7 is 100% free — the full GPL version, not a trial or demo. There are no download limits, no accounts to create, and no upsells during the download.
How do I install Disable XML-RPC-API 2.1.7?
Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.
What are the requirements for Disable XML-RPC-API?
Disable XML-RPC-API 2.1.7 requires WordPress 5.0 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.
When was Disable XML-RPC-API last updated?
Version 2.1.7 was last updated on February 4, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.
Is the Disable XML-RPC-API download safe?
The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.
Technical details
| Version | 2.1.7 |
|---|---|
| Last updated | February 4, 2026 |
| Active installs | 100,000+ |
| Rating | ★★★★☆ 4.2/5 (43 reviews) |
| Requires WordPress | 5.0 or higher |
| Author | Amin Nazemi |
| Tags | disable-xml-rpc, disable-xmlrpc, pingback, stop-brute-force-attacks, xmlrpc |
Download Disable XML-RPC-API
Download Disable XML-RPC-API WP PluginNote: if the download does not start, disable your ad blocker and try again.