Disable XML-RPC Pingback

Disable XML-RPC Pingback

Details
View on WordPress

Stops abuse of your site’s XML-RPC by simply removing some methods used by attackers. While you can use the rest of XML-RPC methods.

This is more friendly than disabling totally XML-RPC, that it’s needed by some plugins and apps (I.e. Mobile apps or some Jetpack’s modules).

  • The original one.
  • Simple and effective.
  • No marketing buzz.
  • Maintained and updated when needed since 2014.
  • 100% compliant with WordPress coding standards which makes it fail safe.
  • 60,000+ active installations can’t be wrong.

If you’re happy with the plugin please don’t forget to give it a good rating, it will motivate me to keep sharing and improving this plugin (and others).

Features

Removes the following methods from XML-RPC interface.

  • pingback.ping
  • pingback.extensions.getPingbacks
  • X-Pingback from HTTP headers. This will hopefully stops some bots from trying to hit your xmlrpc.php file.

Requirements

  • WordPress 3.8.1 or higher.

Details

Plugin code:
disable-xml-rpc-pingback
Plugin version:
1.2.2
Outdated:
No
WP version:
4.8 or higher
PHP version:
5.6 or higher
Test up to WP version:
6.8.3
Total installations:
60,000
Last updated:
2025-11-24
Rating:
Times rated:
14
ddos
pingback
rpc
xml
xml-rpc